Skip to content

Releases: TaliskerMan/ModFS

ModFS Security Hardening Release v1.0.0+15

Choose a tag to compare

@TaliskerMan TaliskerMan released this 21 Apr 19:58

ModFS Release 1.0.0+15

Security Updates & Snyk Audit Report

We are pleased to announce that ModFS version 1.0.0+15 has passed a comprehensive Snyk security scan with 0 vulnerabilities.

Remediated Vulnerabilities

CWE-122: Heap-based Buffer Overflow

Severity: High
Location:

  • src/fsearch_database.c
  • src/test_build/fsearch_database.c

Details:
The application parses a custom binary database format and reads data directly into memory blocks. Manual memcpy operations were previously used without sufficient bounds validation, posing a risk of buffer overflows if the parsed data lengths exceeded the allocated buffers or the end of the memory block.

Remediation:

  • A safe macro, DB_READ_MEM, was introduced to replace all unchecked memcpy operations.
  • DB_READ_MEM enforces strict bounds checking against both the available source memory (end - src) and the destination buffer capacity (dest_size).
  • The macro safely halts processing (src = NULL) if boundaries are violated, preventing unchecked pointer arithmetic and memory corruption.
  • This safe logic was successfully mirrored to the test_build counterparts to ensure uniformity and secure test builds.

Conclusion

With the implementation of the bounds-checked macro, the ModFS database loading routines are significantly hardened against buffer overflow attacks. No further action is required for these findings, and the latest Snyk scan confirms zero vulnerabilities.

ModFS v1.0.0-9

Choose a tag to compare

@TaliskerMan TaliskerMan released this 10 Apr 21:49

Linux Native Release fully compliant with ShadowAgent compliance protocols.