38c0ea3128
That one would also send more data to the other VM that what we intended: the start of the env var data (which in similar code on my host includes the GPG agent socket path, XDG session cookie, and more. The other side expects a fixed size though, so pad with NULs. Interestingly, the original code was not vulnerable as it was callocing enough space. |
||
---|---|---|
archlinux | ||
doc | ||
misc | ||
network | ||
pkgs | ||
qrexec | ||
qubes-rpc | ||
rpm_spec | ||
vm-init.d | ||
vm-systemd | ||
.gitignore | ||
LICENSE | ||
Makefile | ||
Makefile.builder | ||
version |