From: Alexandr Nedvedicky Subject: Re: sys/net/pf_ioctl.c: out of bounds read in pf_rule_copyin To: Johann H??pfner Cc: tech@openbsd.org Date: Wed, 8 Jul 2026 09:57:17 +0200 Hello tech@, On Mon, Jul 06, 2026 at 12:05:31PM +0200, Johann H??pfner wrote: > > I suggest the following fix terminating the fields before strlcpy. A > strscpy-like approach might be cleaner as we discard the return value. > > Index: sys/net/pf_ioctl.c > =================================================================== > --- sys/net/pf_ioctl.c > +++ sys/net/pf_ioctl.c > @@ -4040,6 +4040,15 @@ > > /* XXX union skip[] */ > > + from->label[sizeof(from->label) - 1] = '\0'; > + from->ifname[sizeof(from->ifname) - 1] = '\0'; > + from->rcv_ifname[sizeof(from->rcv_ifname) - 1] = '\0'; > + from->qname[sizeof(from->qname) - 1] = '\0'; > + from->pqname[sizeof(from->pqname) - 1] = '\0'; > + from->tagname[sizeof(from->tagname) - 1] = '\0'; > + from->match_tagname[sizeof(from->match_tagname) - 1] = '\0'; > + from->overload_tblname[sizeof(from->overload_tblname) - 1] = '\0'; > + > strlcpy(to->label, from->label, sizeof(to->label)); > strlcpy(to->ifname, from->ifname, sizeof(to->ifname)); > strlcpy(to->rcv_ifname, from->rcv_ifname, sizeof(to->rcv_ifname)); > I will commit Johann's diff later today unless there will hear objections. thanks and regards sashan