Skip to content

Fix issues on WinDivert::uninstall() - #30

Merged
Rubensei merged 3 commits into
Rubensei:masterfrom
dilluti0n:fix/uninstall
Jul 16, 2026
Merged

Rubensei merged 3 commits into
Rubensei:masterfrom
dilluti0n:fix/uninstall

Conversation

@dilluti0n

Copy link
Copy Markdown
Contributor

This fixes two issues in WinDivert::uninstall():

  1. MaybeUninit::uninit().as_mut_ptr() produces a dangling pointer. The temporary is dropped at the end of the statement, so ControlService() writes through freed stack memory (UB).
  2. The service name passed to OpenServiceA() is a Rust &str without a NUL terminator.

Note: (2) overlaps with #29. It was authored on Jul 13 (see AuthorDate) in dilluti0n/dpibreak@82c8d80, before #29 was opened. I'm upstreaming them together since they touch the same function. Happy to rebase and drop the second commit if #29 is merged first.

MaybeUninit::uninit() is not bound to any variable, so the temporary
is dropped at the end of the statement, leaving `status` as a dangling
pointer into the freed stack slot. Passing it to ControlService() as
an out-pointer then makes the kernel write through a dangling pointer,
which is undefined behavior.

Bind the MaybeUninit<SERVICE_STATUS> to a local so it outlives the
pointer.
@Rubensei

Copy link
Copy Markdown
Owner

It seems I forgot to backport this two fix from the 0.7 prerelease versions

Feel free to bump the MSRV to "1.71", its been long enough since release

Thanks for the contribution!

This should be null terminated or OpenServiceA() have no chance to
know where str is stopped.
@dilluti0n

Copy link
Copy Markdown
Contributor Author

Bumped msrv and changed to "...\0" since c".." is not supported in 1.71.

@Rubensei
Rubensei merged commit c95e52b into Rubensei:master Jul 16, 2026
8 checks passed
@Rubensei Rubensei changed the title Fix pointer issues on WinDivert::uninstall() Fix issues on WinDivert::uninstall() Jul 16, 2026
@dilluti0n
dilluti0n deleted the fix/uninstall branch July 16, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants