Skip to content

Fix: check the result iterator init in print_report_port_xml - #3151

Merged
greenbonebot merged 2 commits into
mainfrom
fix/89-use-of-an-uninitialised-result-iterator-when-init-result-get-iterator-fails
Sep 23, 2026
Merged

greenbonebot merged 2 commits into
mainfrom
fix/89-use-of-an-uninitialised-result-iterator-when-init-result-get-iterator-fails

Conversation

@mattmundell

@mattmundell mattmundell commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

What

In print_report_port_xml, check init_result_get_iterator and, when it
fails, return without using the iterator, leaving a valid empty iterator for
the caller to clean up.

Why

print_report_port_xml ignored init_result_get_iterator's return and then
ran next on the iterator. When the init failed before touching the iterator,
then next and the caller's cleanup_iterator used uninitialised stack memory.

Testing

Before the change, an authenticated

<get_report_ports report_id="..." filt_id="F" details="1"/>

for a report with ports, whose filter F was deleted between the request's
filter validation and the port-iterator init, made gvmd dereference
the uninitialised iterator and abort:

==383==ERROR: AddressSanitizer: SEGV on unknown address ...
    #0 sql_finalize /home/matt/src/gvmd/src/sql_pg.c:766
    #1 cleanup_iterator /home/matt/src/gvmd/src/sql.c:1234
    #2 print_report_port_xml_summary_or_details
        /home/matt/src/gvmd/src/manage_sql_report_ports.c:470
    #3 manage_send_report_ports
        /home/matt/src/gvmd/src/manage_report_ports.c:131
    #4 get_report_ports_run /home/matt/src/gvmd/src/gmp_report_ports.c:155
SUMMARY: AddressSanitizer: SEGV /home/matt/src/gvmd/src/sql_pg.c:766
    in sql_finalize

After the change the same request returns with no ASan report.

print_report_port_xml ignored the return of init_result_get_iterator and
then ran next() on the iterator, which is uninitialised when the init
fails before touching it (eg the filter referred to by get->filt_id was
deleted between the validation and the init).

Return when the init fails, leaving a valid empty iterator for the caller
to clean up.
@mattmundell
mattmundell requested review from a team as code owners September 22, 2026 19:41
@greenbonebot
greenbonebot enabled auto-merge (rebase) September 22, 2026 19:41
Comment thread src/manage_sql_report_ports.c
@greenbonebot
greenbonebot merged commit 4196567 into main Sep 23, 2026
24 of 25 checks passed
@greenbonebot
greenbonebot deleted the fix/89-use-of-an-uninitialised-result-iterator-when-init-result-get-iterator-fails branch September 23, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants