[Bug libc/27083] New: Unsafe unbounded alloca in addmntent
siddhesh at sourceware dot org
sourceware-bugzilla@sourceware.org
Wed Dec 16 14:12:55 GMT 2020
https://sourceware.org/bugzilla/show_bug.cgi?id=27083
Bug ID: 27083
Summary: Unsafe unbounded alloca in addmntent
Product: glibc
Version: unspecified
Status: NEW
Severity: normal
Priority: P2
Component: libc
Assignee: unassigned at sourceware dot org
Reporter: siddhesh at sourceware dot org
CC: drepper.fsp at gmail dot com
Target Milestone: ---
addmntent duplicates strings in its input struct mntent using alloca due to
which very long strings could blow up the stack.
Example:
#include <stdlib.h>
#include <mntent.h>
#include <stdio.h>
#include <string.h>
#define LARGE_VALUE 2*1024*1024*1024ULL
int main(int argc, char **argv) {
FILE *f = fopen("/dev/null", "w");
struct mntent bad;
bad.mnt_fsname = calloc (LARGE_VALUE, 1);
memset (bad.mnt_fsname, ' ', LARGE_VALUE - 1);
bad.mnt_dir = calloc (LARGE_VALUE, 1);
memset (bad.mnt_dir, ' ', LARGE_VALUE - 1);
bad.mnt_type = calloc (LARGE_VALUE, 1);
memset (bad.mnt_type, ' ', LARGE_VALUE - 1);
bad.mnt_opts = calloc (LARGE_VALUE, 1);
memset (bad.mnt_opts, ' ', LARGE_VALUE - 1);
bad.mnt_freq = 1;
bad.mnt_passno = 2;
addmntent (f, &bad);
endmntent(f);
return 0;
}
--
You are receiving this mail because:
You are on the CC list for the bug.
More information about the Glibc-bugs
mailing list