From 3c65b454e4d263f63ecc52fd3e4c3117eb21e5be Mon Sep 17 00:00:00 2001 From: Sean Bright Date: Sat, 8 Aug 2026 20:15:05 +0000 Subject: [PATCH] res_agi.c: Prevent out-of-bounds array access when parsing arguments The `parse_args(...)` function writes to the `argv` array in 2 locations but was only bounds checking in one of them. Moved the bounds check so that it is encountered on each iteration through the parsing loop. Resolves: #2069 --- res/res_agi.c | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/res/res_agi.c b/res/res_agi.c index 5c933acc8e..90eead215f 100644 --- a/res/res_agi.c +++ b/res/res_agi.c @@ -4128,6 +4128,12 @@ static int parse_args(char *s, int *max, const char *argv[]) cur = s; while(*s) { + if (x >= MAX_ARGS - 1) { + ast_log(LOG_WARNING, "Too many arguments, truncating\n"); + x = MAX_ARGS - 1; + break; + } + switch(*s) { case '"': /* If it's escaped, put a literal quote */ @@ -4164,10 +4170,6 @@ static int parse_args(char *s, int *max, const char *argv[]) default: normal: if (whitespace) { - if (x >= MAX_ARGS -1) { - ast_log(LOG_WARNING, "Too many arguments, truncating\n"); - break; - } /* Coming off of whitespace, start the next argument */ argv[x++] = cur; whitespace=0;