[openssh-commits] [openssh] 06/06: upstream: Disallow nul byte in received scp -O filename. Not

git+noreply at mindrot.org git+noreply at mindrot.org
Thu Oct 1 08:51:03 AEST 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit e27b6cc2e6e8ba03808f7078740e5ba800515d4d
Author: dtucker at openbsd.org <dtucker at openbsd.org>
AuthorDate: Sun Sep 27 22:39:40 2026 +0000

    upstream: Disallow nul byte in received scp -O filename. Not
    
    reachable in normal operation since a nul would cause a filename mismatch,
    but potentially possible if being used an unusual configuration such as a
    custom filter.
    
    Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@
    
    OpenBSD-Commit-ID: 1fb35933acdc11dd66bdba780bd9e100bda69079
---
 scp.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/scp.c b/scp.c
index 5c779b92d..cb952f330 100644
--- a/scp.c
+++ b/scp.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: scp.c,v 1.276 2026/09/03 16:02:45 job Exp $ */
+/* $OpenBSD: scp.c,v 1.277 2026/09/27 22:39:40 dtucker Exp $ */
 /*
  * scp - secure remote copy.  This is basically patched BSD rcp which
  * uses ssh to do the data transfer (instead of using rcmd).
@@ -1710,6 +1710,8 @@ sink(int argc, char **argv, const char *src)
 		do {
 			if (atomicio(read, remin, &ch, sizeof(ch)) != sizeof(ch))
 				SCREWUP("lost connection");
+			if (ch == '\0')
+				SCREWUP("nul byte in filename");
 			*cp++ = ch;
 		} while (cp < &buf[sizeof(buf) - 1] && ch != '\n');
 		*cp = 0;

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list