In src/shared/utils.c lines 11-49, the mkdir_r() function allocates a buffer of strlen(path) + 2 bytes for building directory paths, but then uses strcpy() to append path components without bounds checking:
Each strcpy writes without checking if the remaining buffer is large enough. The allocation strlen(path) + 2 barely fits the original path plus a null terminator, but each intermediate directory component is built incrementally by appending to the buffer, potentially overflowing if the path has directory separators in unexpected positions.
Impact
While the specific use case in this codebase is likely safe (paths come from the system and strtok segments the path), this is a latent memory safety bug. An attacker-controlled or unusually structured path could trigger a buffer overflow.
Location
src/shared/utils.c:16-48
Suggested Fix
Replace the manual buffer arithmetic with snprintf() or use asprintf() for safe path construction. Alternatively, allocate using strlen(path) + strlen(path) + 2 (double the path length) for safety margin.
Better: Use a simpler recursive approach that creates directories one at a time, or use snprintf:
This issue was automatically generated by the issue-creator agent.
## Description
In `src/shared/utils.c` lines 11-49, the `mkdir_r()` function allocates a buffer of `strlen(path) + 2` bytes for building directory paths, but then uses `strcpy()` to append path components without bounds checking:
```c
char* path_current = (char*)malloc((strlen(path) + 2) * sizeof(char));
// ...
while (part != NULL) {
strcpy(path_current_position, part); // potential overflow
path_current_position += strlen(part) * sizeof(char);
strcpy(path_current_position, "/"); // potential overflow
path_current_position += sizeof(char);
// ...
part = strtok(NULL, delimiter);
}
```
Each `strcpy` writes without checking if the remaining buffer is large enough. The allocation `strlen(path) + 2` barely fits the original path plus a null terminator, but each intermediate directory component is built incrementally by appending to the buffer, potentially overflowing if the path has directory separators in unexpected positions.
## Impact
While the specific use case in this codebase is likely safe (paths come from the system and `strtok` segments the path), this is a latent memory safety bug. An attacker-controlled or unusually structured path could trigger a buffer overflow.
## Location
`src/shared/utils.c:16-48`
## Suggested Fix
Replace the manual buffer arithmetic with `snprintf()` or use `asprintf()` for safe path construction. Alternatively, allocate using `strlen(path) + strlen(path) + 2` (double the path length) for safety margin.
Better: Use a simpler recursive approach that creates directories one at a time, or use `snprintf`:
```c
char result[PATH_MAX];
int written = snprintf(result, sizeof(result), "%.*s/%.*s", prefix_len, path, part_len, part);
```
## Severity
Medium
## Category
Bug
---
_This issue was automatically generated by the issue-creator agent._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
src/shared/utils.clines 11-49, themkdir_r()function allocates a buffer ofstrlen(path) + 2bytes for building directory paths, but then usesstrcpy()to append path components without bounds checking:Each
strcpywrites without checking if the remaining buffer is large enough. The allocationstrlen(path) + 2barely fits the original path plus a null terminator, but each intermediate directory component is built incrementally by appending to the buffer, potentially overflowing if the path has directory separators in unexpected positions.Impact
While the specific use case in this codebase is likely safe (paths come from the system and
strtoksegments the path), this is a latent memory safety bug. An attacker-controlled or unusually structured path could trigger a buffer overflow.Location
src/shared/utils.c:16-48Suggested Fix
Replace the manual buffer arithmetic with
snprintf()or useasprintf()for safe path construction. Alternatively, allocate usingstrlen(path) + strlen(path) + 2(double the path length) for safety margin.Better: Use a simpler recursive approach that creates directories one at a time, or use
snprintf:Severity
Medium
Category
Bug
This issue was automatically generated by the issue-creator agent.