Commit b21e03d9c8 for asterisk.org

commit b21e03d9c872c2ebc22ea9cfe86a6b10265e46cd
Author: kaelyn ke <313807495+kaelyn-ke@users.noreply.github.com>
Date:   Tue Sep 29 23:30:05 2026 +0800

    app_minivm.c: Fix NULL pointer dereference in MINIVMCOUNTER write

    minivm_counter_func_write() parses its argument as
    account:countername:operand. When the first separator is missing,
    strchr() returns NULL and countername is set to NULL, but it is then
    passed to a second strchr() call. Passing NULL to strchr() is
    undefined behavior and crashes Asterisk.

    Only look for the operand separator after the account/counter
    separator has been found, and initialize operand to NULL so the
    existing argument validation rejects input that never had an operand
    instead of reading an uninitialized pointer.

    Partially addresses #1424

diff --git a/apps/app_minivm.c b/apps/app_minivm.c
index 246bd17434..2febf786a5 100644
--- a/apps/app_minivm.c
+++ b/apps/app_minivm.c
@@ -3301,7 +3301,7 @@ static int minivm_counter_func_read(struct ast_channel *chan, const char *cmd, c
 /*! \brief  ${MINIVMCOUNTER()} Dialplan function - changes counter data */
 static int minivm_counter_func_write(struct ast_channel *chan, const char *cmd, char *data, const char *value)
 {
-	char *username, *domain, *countername, *operand;
+	char *username, *domain, *countername, *operand = NULL;
 	char userpath[BUFSIZ];
 	int change = 0;
 	int operation = 0;
@@ -3315,10 +3315,11 @@ static int minivm_counter_func_write(struct ast_channel *chan, const char *cmd,
 	if ((countername = strchr(username, ':'))) {
 		*countername = '\0';
 		countername++;
-	}
-	if ((operand = strchr(countername, ':'))) {
-		*operand = '\0';
-		operand++;
+
+		if ((operand = strchr(countername, ':'))) {
+			*operand = '\0';
+			operand++;
+		}
 	}

 	if ((domain = strchr(username, '@'))) {