Skip to content

CVE-2024-10964: v2.8 plugin_handle.c still uses unbounded strcpy() — backport request #2743

Description

@vulgraph

Hello,

Follow-up scan after looking at v2.9 — the same CVE-2024-10964 fix is also missing on the older v2.8 branch.

Upstream fix: 3e3a583d — plugin:buffer overflow (replaces strcpy() with strncpy(..., NEU_PLUGIN_LIBRARY_LEN)).

State on v2.8 (HEAD 6c58bfe2128a):

function line on v2.8
handle_add_plugin strcpy(cmd.library, req->library);
handle_update_plugin strcpy(cmd.library, req->library);

Both still call the unbounded strcpy() against attacker-controllable req->library, so the original buffer-overflow condition is reachable.

compare v2.8...main reports diverged, ahead=698, behind=148, so the branch is actively maintained.

The minimum diff is identical to the upstream +2/-2 change in plugins/restful/plugin_handle.c; the master-only otel_trace_type field is not on v2.8 and is not needed.

Happy to send the cherry-pick as a PR if that helps. Thanks for maintaining v2.x!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions