Ge-org Brohammer 26d38779e4 realtek: Fix use-after-free of the SSM error in completion handlers
fp_verify_ssm_done(), fp_enroll_ssm_done(), fp_init_ssm_done() and
fp_delete_ssm_done() each overwrite the GError they are given:

  if (fpi_ssm_get_error (ssm))
    error = fpi_ssm_get_error (ssm);

An SSM completion callback is handed an owned copy of the error --
fpi-ssm.c takes a g_error_copy() before invoking the callback -- whereas
fpi_ssm_get_error() is documented as (transfer none), and the machine's
own error is freed by the fpi_ssm_free() that immediately follows the
callback.

Since every fpi_device_*_complete() takes the error as (transfer full),
these handlers leak the copy they own and hand the consumer a pointer
that is freed moments later. The consumer is then left reading a
dangling GError. For fprintd that is fatal: it logs error->message and
dies with a general protection fault inside strlen(), taking the
session's authentication daemon with it.

  kernel: traps: fprintd[67901] general protection fault
                 ip:7fcef3b6429c sp:7ffd5f4128a8 error:0 in libc.so.6

  #0  __strlen_evex ()
  #3  g_vasprintf () at ../glib/gprintf.c:342
  #5  g_strdup_vprintf () at ../glib/gstrfuncs.c:515
  #9  delete_enrolled_fingers (user=... "ge-org",
                               finger=FP_FINGER_RIGHT_INDEX)
        at ../src/device.c:2420
        local_error = 0x563c2628bcb0

The assignment is redundant even where it is not harmful, because the
error passed to the callback is already a copy of the machine's error;
using it directly is both correct and sufficient. fpi_ssm_dup_error()
is available for callers that do need an owned copy. No other driver in
the tree assigns the borrowed SSM error this way.

Reproduced on a Realtek 2541:fa03 (Minisforum AI X1 Pro 470) by
enrolling a finger while a template was already present in on-chip
storage, which takes the delete path shown above. The same driver bug
reaches fprintd a second way, via fp_enroll_ssm_done() ->
fpi_device_enroll_complete() -> fprintd's enroll_cb().
2026-08-28 13:30:33 +02:00
2012-12-14 13:17:24 +01:00
2007-11-15 09:54:35 +00:00
2018-05-18 01:16:30 +02:00
2020-05-22 15:00:11 +02:00
2026-07-26 00:36:25 +02:00
2026-07-26 00:36:11 +02:00
2024-05-03 15:35:11 +02:00

LibFPrint

LibFPrint is part of the FPrint project.


Button Website Button Documentation

Button Supported Button Unsupported

Button Contribute Button Contributors

History

LibFPrint was originally developed as part of an academic project at the University Of Manchester.

It aimed to hide the differences between consumer fingerprint scanners and provide a single uniform API to application developers.

Goal

The ultimate goal of the FPrint project is to make fingerprint scanners widely and easily usable under common Linux environments.

License

Section 6 of the license states that for compiled works that use this library, such works must include LibFPrint copyright notices alongside the copyright notices for the other parts of the work.

LibFPrint includes code from NIST's NBIS software distribution.

We include Bozorth3 from the US Export Controlled distribution, which we have determined to be fine being shipped in an open source project.

Get in touch

  • IRC - #fprint @ irc.oftc.net
  • Matrix - #fprint:matrix.org bridged to the IRC channel
  • MailingList - low traffic, not much used these days

Badge License

S
Description
Library for fingerprint readers For unsupported devices, please see/edit https://gitlab.freedesktop.org/libfprint/wiki/-/wikis/Unsupported%20Devices Do **not** open issues for unsupported devices that are already listed in the wiki page. For other devices, please simply add them to the wiki rather than opening a bug report here. Opening an issue to ask for a driver will not have any effect other than taking time from developers who need to close the issue again.
Readme
32 MiB
Languages
C 95.5%
Python 3.3%
Meson 0.9%
Shell 0.2%