[Bug libc/27083] New: Unsafe unbounded alloca in addmntent

siddhesh at sourceware dot org sourceware-bugzilla@sourceware.org
Wed Dec 16 14:12:55 GMT 2020


https://sourceware.org/bugzilla/show_bug.cgi?id=27083

            Bug ID: 27083
           Summary: Unsafe unbounded alloca in addmntent
           Product: glibc
           Version: unspecified
            Status: NEW
          Severity: normal
          Priority: P2
         Component: libc
          Assignee: unassigned at sourceware dot org
          Reporter: siddhesh at sourceware dot org
                CC: drepper.fsp at gmail dot com
  Target Milestone: ---

addmntent duplicates strings in its input struct mntent using alloca due to
which very long strings could blow up the stack.

Example:

#include <stdlib.h>
#include <mntent.h>
#include <stdio.h>
#include <string.h>

#define LARGE_VALUE 2*1024*1024*1024ULL

int main(int argc, char **argv) {
  FILE *f = fopen("/dev/null", "w");
  struct mntent bad;

  bad.mnt_fsname = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_fsname, ' ', LARGE_VALUE - 1);
  bad.mnt_dir = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_dir, ' ', LARGE_VALUE - 1);
  bad.mnt_type = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_type, ' ', LARGE_VALUE - 1);
  bad.mnt_opts = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_opts, ' ', LARGE_VALUE - 1);
  bad.mnt_freq = 1;
  bad.mnt_passno = 2;

  addmntent (f, &bad);

  endmntent(f);

  return 0;
}

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Glibc-bugs mailing list