[Bug network/14889] svc_run() produces high cpu usage when accept() fails with EMFILE (CVE-2011-4609)

cvs-commit at gcc dot gnu.org sourceware-bugzilla@sourceware.org
Thu Dec 10 10:13:16 GMT 2020


https://sourceware.org/bugzilla/show_bug.cgi?id=14889

--- Comment #5 from cvs-commit at gcc dot gnu.org <cvs-commit at gcc dot gnu.org> ---
The master branch has been updated by Stefan Liebler <stli@sourceware.org>:

https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=4b2e40a9259fab08161e1c607b06a41e15d543dc

commit 4b2e40a9259fab08161e1c607b06a41e15d543dc
Author: Stefan Liebler <stli@linux.ibm.com>
Date:   Fri Dec 4 17:00:27 2020 +0100

    Handle out-of-memory case in svc_tcp.c/svc_unix.c:rendezvous_request.

    If glibc is build with -O3 on at least 390 (-m31) or x86 (-m32),
    gcc 11 dumps this warning:
    svc_tcp.c: In function 'rendezvous_request':
    svc_tcp.c:274:3: error: 'memcpy' offset [0, 15] is out of the bounds [0, 0]
[-Werror=array-bounds]
      274 |   memcpy (&xprt->xp_raddr, &addr, sizeof (addr));
          |   ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    cc1: all warnings being treated as errors

    In out-of-memory case, if one of the mallocs in makefd_xprt function
    returns NULL, a message is dumped, makefd_xprt returns NULL
    and the subsequent memcpy would copy to NULL.

    Instead of a segfaulting, we delay a bit (see also __svc_accept_failed
    and Bug 14889 (CVE-2011-4609) - svc_run() produces high cpu usage when
    accept() fails with EMFILE (CVE-2011-4609).

    The same applies to svc_unix.c.
    Reviewed-by: Adhemerval Zanella  <adhemerval.zanella@linaro.org>

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Glibc-bugs mailing list