[PATCH] gen_init_cpio: stop parsing on lines with a missing argument list

From: lzhan011

Date: Mon Oct 05 2026 - 05:01:31 EST


When a line in the cpio list consists of a file type followed only by
whitespace and no newline (e.g. "slink " as the last line of the file),
strtok(NULL, "\n") returns NULL. main() prints an error and sets ec, but
then carries on and passes the NULL args pointer to the type handler,
which hands it to sscanf() and crashes:

AddressSanitizer: SEGV on unknown address 0x000000000000
#4 __isoc99_sscanf
#5 cpio_mkslink_line usr/gen_init_cpio.c:169

Break out of the loop as is already done for the other format error, so
that the error is reported and gen_init_cpio exits with a failure status.

Found by fuzzing gen_init_cpio built with ASan/UBSan.

Reproducer:
printf 'slink ' > list && usr/gen_init_cpio list

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan
Signed-off-by: lzhan011 <lzsx618@xxxxxxxxx>
---
usr/gen_init_cpio.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/usr/gen_init_cpio.c b/usr/gen_init_cpio.c
index b7296edc6..0f0c61ec2 100644
--- a/usr/gen_init_cpio.c
+++ b/usr/gen_init_cpio.c
@@ -756,6 +756,7 @@ int main (int argc, char *argv[])
"ERROR: incorrect format, newline required line %d: '%s'\n",
line_nr, line);
ec = -1;
+ break;
}

for (type_idx = 0; file_handler_table[type_idx].type; type_idx++) {
--
2.34.1