Commit b21e03d9c8 for asterisk.org
commit b21e03d9c872c2ebc22ea9cfe86a6b10265e46cd
Author: kaelyn ke <313807495+kaelyn-ke@users.noreply.github.com>
Date: Tue Sep 29 23:30:05 2026 +0800
app_minivm.c: Fix NULL pointer dereference in MINIVMCOUNTER write
minivm_counter_func_write() parses its argument as
account:countername:operand. When the first separator is missing,
strchr() returns NULL and countername is set to NULL, but it is then
passed to a second strchr() call. Passing NULL to strchr() is
undefined behavior and crashes Asterisk.
Only look for the operand separator after the account/counter
separator has been found, and initialize operand to NULL so the
existing argument validation rejects input that never had an operand
instead of reading an uninitialized pointer.
Partially addresses #1424
diff --git a/apps/app_minivm.c b/apps/app_minivm.c
index 246bd17434..2febf786a5 100644
--- a/apps/app_minivm.c
+++ b/apps/app_minivm.c
@@ -3301,7 +3301,7 @@ static int minivm_counter_func_read(struct ast_channel *chan, const char *cmd, c
/*! \brief ${MINIVMCOUNTER()} Dialplan function - changes counter data */
static int minivm_counter_func_write(struct ast_channel *chan, const char *cmd, char *data, const char *value)
{
- char *username, *domain, *countername, *operand;
+ char *username, *domain, *countername, *operand = NULL;
char userpath[BUFSIZ];
int change = 0;
int operation = 0;
@@ -3315,10 +3315,11 @@ static int minivm_counter_func_write(struct ast_channel *chan, const char *cmd,
if ((countername = strchr(username, ':'))) {
*countername = '\0';
countername++;
- }
- if ((operand = strchr(countername, ':'))) {
- *operand = '\0';
- operand++;
+
+ if ((operand = strchr(countername, ':'))) {
+ *operand = '\0';
+ operand++;
+ }
}
if ((domain = strchr(username, '@'))) {