fio: fix CVE-2025-10823

Reference:
	https://nvd.nist.gov/vuln/detail/CVE-2025-10823
	https://github.com/axboe/fio/issues/1982

Upstream-patch:
	6a39dfaffd

Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
This commit is contained in:
Saravanan 2025-10-15 11:44:24 +05:30 committed by Anuj Mittal
parent 94867425c1
commit e599281324
No known key found for this signature in database
GPG Key ID: B749E1556041E1B2
2 changed files with 39 additions and 0 deletions

View File

@ -0,0 +1,37 @@
From 6a39dfaffdb8a6c2080eec0dc7fb1ee532d54025 Mon Sep 17 00:00:00 2001
From: Jens Axboe <axboe@kernel.dk>
Date: Tue, 23 Sep 2025 11:50:46 -0600
Subject: [PATCH] options: check for NULL input string and fail
Waste of time busy work.
Link: https://github.com/axboe/fio/issues/1982
CVE: CVE-2025-10823
Upstream-Status: Backport
https://github.com/axboe/fio/commit/6a39dfaffdb8a6c2080eec0dc7fb1ee532d54025
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Saravanan <saravanan.kadambathursubramaniyam@windriver.com>
---
options.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/options.c b/options.c
index de935ef..b38441e 100644
--- a/options.c
+++ b/options.c
@@ -1535,6 +1535,9 @@ static int str_buffer_pattern_cb(void *data, const char *input)
struct thread_data *td = cb_data_to_td(data);
int ret;
+ if (!input)
+ return 1;
+
/* FIXME: for now buffer pattern does not support formats */
ret = parse_and_fill_pattern_alloc(input, strlen(input),
&td->o.buffer_pattern, NULL, NULL, NULL);
--
2.44.3

View File

@ -28,6 +28,8 @@ SRC_URI = "git://git.kernel.dk/fio.git;branch=master"
S = "${WORKDIR}/git"
SRC_URI += "file://CVE-2025-10823.patch"
# avoids build breaks when using no-static-libs.inc
DISABLE_STATIC = ""