From f5bbae0ef3ee61ef8ea71fb38210c1b31f7ec0f4 Mon Sep 17 00:00:00 2001 From: Dom Cobley Date: Fri, 2 Oct 2026 15:45:26 +0100 Subject: [PATCH] vcgencmd: Fix off-by-one when copying gencmd response strncat(dst, src, n) can write n characters plus a terminator, so passing the full buffer size could write one byte past the end of result. It also triggers -Wstringop-truncation/-Wstringop-overflow. Copy a bounded length with memcpy and terminate explicitly. Fixes: #197 --- vcgencmd/vcgencmd.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/vcgencmd/vcgencmd.c b/vcgencmd/vcgencmd.c index 63faf2e..1c25781 100644 --- a/vcgencmd/vcgencmd.c +++ b/vcgencmd/vcgencmd.c @@ -109,8 +109,11 @@ static unsigned gencmd(int file_desc, const char *command, char *result, int res p[0] = i*sizeof *p; // actual size mbox_property(file_desc, p); - result[0] = 0; - strncat(result, (const char *)(p+6), result_len); + len = strnlen((const char *)(p+6), MAX_STRING); + if (len >= result_len) + len = result_len - 1; + memcpy(result, p+6, len); + result[len] = 0; return p[5]; }