[openssh-commits] [openssh] 06/06: upstream: Disallow nul byte in received scp -O filename. Not
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 08:51:03 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit e27b6cc2e6e8ba03808f7078740e5ba800515d4d
Author: dtucker at openbsd.org <dtucker at openbsd.org>
AuthorDate: Sun Sep 27 22:39:40 2026 +0000
upstream: Disallow nul byte in received scp -O filename. Not
reachable in normal operation since a nul would cause a filename mismatch,
but potentially possible if being used an unusual configuration such as a
custom filter.
Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@
OpenBSD-Commit-ID: 1fb35933acdc11dd66bdba780bd9e100bda69079
---
scp.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/scp.c b/scp.c
index 5c779b92d..cb952f330 100644
--- a/scp.c
+++ b/scp.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: scp.c,v 1.276 2026/09/03 16:02:45 job Exp $ */
+/* $OpenBSD: scp.c,v 1.277 2026/09/27 22:39:40 dtucker Exp $ */
/*
* scp - secure remote copy. This is basically patched BSD rcp which
* uses ssh to do the data transfer (instead of using rcmd).
@@ -1710,6 +1710,8 @@ sink(int argc, char **argv, const char *src)
do {
if (atomicio(read, remin, &ch, sizeof(ch)) != sizeof(ch))
SCREWUP("lost connection");
+ if (ch == '\0')
+ SCREWUP("nul byte in filename");
*cp++ = ch;
} while (cp < &buf[sizeof(buf) - 1] && ch != '\n');
*cp = 0;
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list