Skip to content

[22843]+[22844] Solve fuzz XMLParser Null-dereference (backport #5668) #5683

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 6, 2025

Conversation

mergify[bot]
Copy link
Contributor

@mergify mergify bot commented Mar 5, 2025

Description

This PR solves two Null-dereference issues from the XMLParser found in oss-fuzz. Added regression test, and fixed by adding an error message preventing an empty map to be built.

@Mergifyio backport 3.1.x 2.14.x 2.10.x

Contributor Checklist

  • Commit messages follow the project guidelines.

  • The code follows the style guidelines of this project.

  • Tests that thoroughly check the new feature have been added/Regression tests checking the bug and its fix have been added; the added tests pass locally

  • N/A Any new/modified methods have been properly documented using Doxygen.

  • N/A Any new configuration API has an equivalent XML API (with the corresponding XSD extension)

  • Changes are backport compatible: they do NOT break ABI nor change library core behavior.

  • Changes are API compatible.

  • N/A New feature has been added to the versions.md file (if applicable).

  • N/A New feature has been documented/Current behavior is correctly described in the documentation.

  • Applicable backports have been included in the description.

Reviewer Checklist

  • The PR has a milestone assigned.
  • The title and description correctly express the PR's purpose.
  • Check contributor checklist is correct.
  • If this is a critical bug fix, backports to the critical-only supported branches have been requested.
  • Check CI results: changes do not issue any warning.
  • Check CI results: failing tests are unrelated with the changes.

This is an automatic backport of pull request #5668 done by [Mergify](https://mergify.com).

* Refs 22843+22844: Regression test

Signed-off-by: Juanjo Garcia <[email protected]>

* Refs 22843+22844: Fix

Signed-off-by: Juanjo Garcia <[email protected]>

---------

Signed-off-by: Juanjo Garcia <[email protected]>
(cherry picked from commit dc26c40)
@juanjo4936 juanjo4936 added this to the v3.1.3 milestone Mar 5, 2025
@juanjo4936 juanjo4936 requested a review from richiprosima March 5, 2025 07:34
@github-actions github-actions bot added the ci-pending PR which CI is running label Mar 5, 2025
@juanjo4936 juanjo4936 merged commit 735a643 into 3.1.x Mar 6, 2025
17 checks passed
@juanjo4936 juanjo4936 deleted the mergify/bp/3.1.x/pr-5668 branch March 6, 2025 14:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci-pending PR which CI is running
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants