Skip to content

Release 2.9.0 - #37

Closed
bunnam988 wants to merge 5 commits into
mainfrom
release/2.9.0
Closed

bunnam988 wants to merge 5 commits into
mainfrom
release/2.9.0

Conversation

@bunnam988

Copy link
Copy Markdown
Contributor

Release 2.9.0

pavankumar464 and others added 5 commits August 17, 2026 12:39
…y source paths (#31)

Reason for change: Address PRs native builds failing in the javascript-templates

Test Procedure: PRs native builds should pass for javascript-templates

Risks: Low

Priority: P2

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
RDKB-65597 : [Risk-High] Fixing JST (Generic) Security Fuzzing Report

Reason for change:
Root Cause: ftell() causing calloc() to request an enormous allocation
and trigger an OOM abort.
Recommendation - Check `ftell()` return value for `-1` before using it
as allocation size:

Root Cause: `strtok()` on const/env Memory
Recommendation - Replace destructive strtok() parsing with read-only
boundary detection using strchr(), copy the session ID into a local
writable buffer, and use that buffer for validation and file lookup.

Root Cause: Session identifier validation can be bypassed, potentially
allowing session hijacking.
Recommendation - Check Session IDs length and prefix, it should contain
only alphanumeric suffix characters, avoid in-place cookie modification
during parsing, and are accepted only if the corresponding session file
exists.

Test Procedure: WebGUI should work as expected
Risks: Medium
Priority: P1

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Reason for change: Fix session ID format before handling
Test Procedure: Test for session identifier
Risks: High
Priority: P1
Fixed Heap Buffer Overflow in `do_openssl_verify_with_cert`
Recommendation - Check `strlen(filepath) >= 7` before calling `memcmp`,
or use `strncmp` which handles short strings safely

Fixed Command Injection via `popen()`
Recommendation - Never pass untrusted input to `popen()` — use
`execve()` with argument arrays or sanitize input

---------

Co-authored-by: anoopchelakkode <65686868+anoopchelakkode@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 21, 2026 07:03
@bunnam988
bunnam988 requested a review from a team as a code owner August 21, 2026 07:03
@bunnam988 bunnam988 closed this Aug 21, 2026
@bunnam988
bunnam988 deleted the release/2.9.0 branch August 21, 2026 07:03
@github-actions

Copy link
Copy Markdown

📋 PR Format Reminder

  • Title: Release 2.9.0 — expected TICKET-123 : description
    (Multiple tickets OK: RDKCOM-5492 RDKBDEV-3336 : ... | Include US ticket + subtask for user-stories)
  • Description missing:
    • Reason for change
    • Test Procedure
    • Risks (Low / Medium / High)
    • Priority (P0 / P1 / P2)

Expected:

TICKET-123 : brief description

Reason for change: why
Test Procedure: how to verify
Risks: Low / Medium / High
Priority: P0 / P1 / P2

@github-actions github-actions Bot locked and limited conversation to collaborators Aug 21, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants