From 22079ca863da9519530148418bdaeb99bdc872dd Mon Sep 17 00:00:00 2001 From: Ben Meadors Date: Wed, 12 Aug 2026 19:13:07 -0500 Subject: [PATCH] fix(platform): OOM null-write in stm32wl File and exception leak in portduino GPIO init (#11456) - STM32_LittleFS File::_open_dir: the _dir_path allocation was the only unchecked malloc in the file, followed immediately by strcpy - an OOM became a NULL write, and the half-initialized state (open dir, null path) would later feed strlen(NULL) in openNextFile(). Check it and unwind the already-opened dir, matching the sibling failure path. - PortduinoGlue initGPIOPin: if setSilent()/gpioBind() threw after the LinuxGPIOPin was constructed, the pointer was lost in the catch block. Hold it in a unique_ptr and release only after the gpio table takes ownership. --- src/platform/portduino/PortduinoGlue.cpp | 6 +++--- src/platform/stm32wl/STM32_LittleFS_File.cpp | 11 +++++++++-- 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/src/platform/portduino/PortduinoGlue.cpp b/src/platform/portduino/PortduinoGlue.cpp index 3076be764..df977a028 100644 --- a/src/platform/portduino/PortduinoGlue.cpp +++ b/src/platform/portduino/PortduinoGlue.cpp @@ -845,10 +845,10 @@ int initGPIOPin(int pinNum, const std::string &gpioChipName, int line) std::string gpio_name = "GPIO" + std::to_string(pinNum); std::cout << "Initializing " << gpio_name << " on chip " << gpioChipName << std::endl; try { - GPIOPin *csPin; - csPin = new LinuxGPIOPin(pinNum, gpioChipName.c_str(), line, gpio_name.c_str()); + auto csPin = std::make_unique(pinNum, gpioChipName.c_str(), line, gpio_name.c_str()); csPin->setSilent(); - gpioBind(csPin); + gpioBind(csPin.get()); + csPin.release(); // owned by the gpio table from here on return ERRNO_OK; } catch (...) { const std::type_info *t = abi::__cxa_current_exception_type(); diff --git a/src/platform/stm32wl/STM32_LittleFS_File.cpp b/src/platform/stm32wl/STM32_LittleFS_File.cpp index 1f8ae1dea..dfe04aaf1 100644 --- a/src/platform/stm32wl/STM32_LittleFS_File.cpp +++ b/src/platform/stm32wl/STM32_LittleFS_File.cpp @@ -100,11 +100,18 @@ bool File::_open_dir(char const *filepath) return false; } - _is_dir = true; - _dir_path = (char *)rtos_malloc(strlen(filepath) + 1); + if (!_dir_path) { + // match the _dir failure path above: don't leave a half-open dir behind + lfs_dir_close(_fs->_getFS(), _dir); + rtos_free(_dir); + _dir = NULL; + return false; + } strcpy(_dir_path, filepath); + _is_dir = true; + return true; }