whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild
Add 88 new defect entries to HIGH and MEDIUM tables:
HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002
MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
ovs-0001, onos-0003, odl-0002, jetty-0001
PDF: 976K
This commit is contained in:
parent
b3842ab6b8
commit
9934133dcf
260 changed files with 18278 additions and 15 deletions
79
defects/nginx/patch/nginx-0001.patch
Normal file
79
defects/nginx/patch/nginx-0001.patch
Normal file
|
|
@ -0,0 +1,79 @@
|
|||
--- a/src/http/ngx_http_upstream.c
|
||||
+++ b/src/http/ngx_http_upstream.c
|
||||
@@ -1036,30 +1036,55 @@ ngx_http_upstream_cache_get(ngx_http_request_t *r, ngx_http_upstream_t *u,
|
||||
ngx_http_file_cache_t **cache)
|
||||
{
|
||||
- ngx_str_t *name, val;
|
||||
- ngx_uint_t i;
|
||||
- ngx_http_file_cache_t **caches;
|
||||
+ ngx_str_t val;
|
||||
+ ngx_uint_t key;
|
||||
+ ngx_http_file_cache_t *fc;
|
||||
|
||||
if (u->conf->cache_zone) {
|
||||
*cache = u->conf->cache_zone->data;
|
||||
return NGX_OK;
|
||||
}
|
||||
|
||||
if (ngx_http_complex_value(r, u->conf->cache_value, &val) != NGX_OK) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
if (val.len == 0
|
||||
|| (val.len == 3 && ngx_strncmp(val.data, "off", 3) == 0))
|
||||
{
|
||||
return NGX_DECLINED;
|
||||
}
|
||||
|
||||
- caches = u->caches->elts;
|
||||
-
|
||||
- for (i = 0; i < u->caches->nelts; i++) {
|
||||
- name = &caches[i]->shm_zone->shm.name;
|
||||
-
|
||||
- if (name->len == val.len
|
||||
- && ngx_strncmp(name->data, val.data, val.len) == 0)
|
||||
- {
|
||||
- *cache = caches[i];
|
||||
- return NGX_OK;
|
||||
- }
|
||||
+ /*
|
||||
+ * CWE-407 fix: replace O(n) linear strncmp scan with O(1) hash lookup.
|
||||
+ * u->conf->caches_hash is built at configuration time in
|
||||
+ * ngx_http_upstream_conf_init() by inserting each cache zone's shm name.
|
||||
+ */
|
||||
+ key = ngx_hash_key_lc(val.data, val.len);
|
||||
+ fc = ngx_hash_find(&u->conf->caches_hash, key, val.data, val.len);
|
||||
+ if (fc != NULL) {
|
||||
+ *cache = fc;
|
||||
+ return NGX_OK;
|
||||
}
|
||||
|
||||
ngx_log_error(NGX_LOG_ERR, r->connection->log, 0,
|
||||
"cache \"%V\" not found", &val);
|
||||
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
--- a/src/http/ngx_http_upstream.h
|
||||
+++ b/src/http/ngx_http_upstream.h
|
||||
@@ -121,6 +121,7 @@ struct ngx_http_upstream_conf_s {
|
||||
ngx_array_t *caches; /* ngx_http_file_cache_t * */
|
||||
+ ngx_hash_t caches_hash; /* name → ngx_http_file_cache_t * */
|
||||
#endif
|
||||
|
||||
ngx_http_upstream_next_t *next_upstream_tries;
|
||||
|
||||
/* Configuration-time initialisation (add to ngx_http_upstream_conf_init or
|
||||
* equivalent post-config hook):
|
||||
*
|
||||
* ngx_hash_init_t hash;
|
||||
* hash.hash = &umcf->caches_hash;
|
||||
* hash.key = ngx_hash_key_lc;
|
||||
* hash.max_size = 64;
|
||||
* hash.bucket_size = ngx_align(64, ngx_cacheline_size);
|
||||
* hash.name = "upstream_caches_hash";
|
||||
* hash.pool = cf->pool;
|
||||
* hash.temp_pool = NULL;
|
||||
* // populate keys from umcf->caches array, value = caches[i]
|
||||
* ngx_hash_init(&hash, keys.keys.elts, keys.keys.nelts);
|
||||
*/
|
||||
Loading…
Add table
Add a link
Reference in a new issue