The client of the future https://irssi.org
  • C 90.6%
  • XS 3.4%
  • Perl 2.1%
  • Meson 2%
  • Prolog 1.5%
  • Other 0.4%
Find a file
Acts1631 27f857e37b otr: fix off-by-one in reassembly buffer growth check (heap overflow)
In enqueue_otr_fragment(), once a ?OTR: reassembly is open, each
continuation fragment is appended to opc->full_msg and the buffer is
grown only if there isn't enough room:

    if (msg_len > (opc->msg_size - opc->msg_len)) { realloc(...); }
    memcpy(opc->full_msg + opc->msg_len, msg, msg_len);
    opc->msg_len += msg_len;
    opc->full_msg[opc->msg_len] = '\0';

The comparison uses '>' instead of '>='. When a fragment's length is
exactly equal to the remaining space (opc->msg_size - opc->msg_len),
the condition is false, so no realloc happens; the memcpy itself still
fits, but the following NUL-terminator write at
opc->full_msg[opc->msg_len] lands exactly one byte past the end of the
allocation, corrupting the adjacent heap chunk.

This is remotely reachable the same way as the other reassembly bugs
in this file: any user who can send the victim a private message can
drive the running remaining-space counter to land on an exact match
(remaining space grows by a small, attacker-observable amount on every
realloc, and fragment lengths are fully attacker controlled), then send
one more fragment of that exact length to trigger the overflow.

Fix the comparison to '>=' so the buffer is grown whenever there isn't
room for both the fragment bytes and the terminator.
2026-07-06 10:41:17 -04:00
.github/workflows Add muon fmt GitHub Actions workflow 2026-01-26 21:02:10 -08:00
.obs test OBS workflow 2022-05-19 14:37:59 +02:00
docs run meson formatter 2026-01-25 22:07:44 +01:00
fuzz-support Fix some glib deprecation warnings 2019-10-31 23:49:40 +01:00
scripts run meson formatter 2026-01-25 22:07:44 +01:00
src otr: fix off-by-one in reassembly buffer growth check (heap overflow) 2026-07-06 10:41:17 -04:00
subprojects up glib wrap 2026-01-23 21:21:10 +01:00
tests run meson formatter 2026-01-25 22:07:44 +01:00
themes run meson formatter 2026-01-25 22:07:44 +01:00
utils fix clang-format-xs boot code 2026-01-24 20:53:29 +01:00
.clang-format fix clang formatting 2021-04-01 21:21:06 +02:00
.gitattributes Add .gitattributes to ensure all shell scripts have LF as eol-style. 2016-01-31 20:49:59 +02:00
.gitignore good-bye and thanks, autotools 2022-02-19 21:44:10 +01:00
.muon_fmt.ini run meson formatter 2026-01-25 22:07:44 +01:00
AUTHORS Add OTR support. 2018-02-26 23:32:57 +01:00
COPYING Update FSF address. 2007-05-08 17:51:51 +00:00
INSTALL Add a few more compile dependencies to INSTALL document 2026-01-23 22:17:39 +01:00
irssi-icon.png New icon by ditCh. 2008-03-04 17:46:11 +00:00
irssi.conf new SHELP default alias 2022-04-24 15:40:20 +02:00
MANIFEST.in Add some missing files to make-dist 2022-02-20 18:55:45 +01:00
meson.build Format root meson.build 2026-01-26 21:02:10 -08:00
meson_options.txt remove deprecated defines 2022-02-20 17:33:36 +01:00
NEWS Merge tag '1.4.5' into integrate/1.4.5 2023-10-01 19:19:33 +02:00
README.md Update minimum required Perl version in readme 2024-04-01 22:10:35 +02:00
TODO Add todo for gnutls. 2008-03-30 13:53:33 +00:00

Irssi

Build Status

Irssi is a modular text mode chat client. It comes with IRC support built in, and there are third party ICB, SILC, XMPP (Jabber), PSYC and Quassel protocol modules available.

irssi

Download information

Development source installation

Ninja 1.8 and Meson 0.53

git clone https://github.com/irssi/irssi
cd irssi
meson Build
ninja -C Build && sudo ninja -C Build install

Release source installation

  • Download release
  • Verify signature
tar xJf irssi-*.tar.xz
cd irssi-*
meson Build
ninja -C Build && sudo ninja -C Build install

Requirements

See the INSTALL file for details

Documentation

Themes

Scripts

Modules

Security information

Please report security issues to staff@irssi.org. Thanks!

Bugs / Suggestions / Contributing

Check the GitHub issues if it is already listed in there; if not, open an issue on GitHub or send a mail to staff@irssi.org.

Irssi is always looking for developers. Feel free to submit patches through GitHub pull requests.

You can also contact the Irssi developers in #irssi on irc.libera.chat.