From b4781e0070d1f37fc83e1fe1d92206139168013a Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 05:15:27 +0000 Subject: [PATCH] fix(OSQUERY-003): genSudoersFile ignores unchecked substr/at() calls on possibly malformed sudoers lines --- osquery/tables/system/posix/sudoers.cpp | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/osquery/tables/system/posix/sudoers.cpp b/osquery/tables/system/posix/sudoers.cpp index 43d7abaf564..0b51bf0a3f9 100644 --- a/osquery/tables/system/posix/sudoers.cpp +++ b/osquery/tables/system/posix/sudoers.cpp @@ -117,11 +117,16 @@ void genSudoersFile(const std::string& filename, if (is_includedir) { // support both relative and full paths - if (rule_details.at(0) != '/') { + if (!rule_details.empty() && rule_details.at(0) != '/') { auto path = fs::path(filename).parent_path() / rule_details; rule_details = path.string(); } + if (rule_details.empty()) { + TLOG << "Empty includedir target in sudoers file: " << filename; + continue; + } + std::vector inc_files; if (!listFilesInDirectory(rule_details, inc_files).ok()) { TLOG << "Could not list includedir: " << rule_details; @@ -144,11 +149,16 @@ void genSudoersFile(const std::string& filename, } if (is_include) { // support both relative and full paths - if (rule_details.at(0) != '/') { + if (!rule_details.empty() && rule_details.at(0) != '/') { auto path = fs::path(filename).parent_path() / rule_details; rule_details = path.string(); } + if (rule_details.empty()) { + TLOG << "Empty include target in sudoers file: " << filename; + continue; + } + genSudoersFile(rule_details, ++level, results); } } @@ -167,3 +177,4 @@ QueryData genSudoers(QueryContext& context) { } } // namespace tables } // namespace osquery +