[Bug stdio/28828] fputwc crashes

cvs-commit at gcc dot gnu.org sourceware-bugzilla@sourceware.org
Tue Mar 8 17:26:15 GMT 2022


https://sourceware.org/bugzilla/show_bug.cgi?id=28828

--- Comment #2 from cvs-commit at gcc dot gnu.org <cvs-commit at gcc dot gnu.org> ---
The master branch has been updated by Adhemerval Zanella
<azanella@sourceware.org>:

https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=edc696a73a7cb07b1aa68792a845a98d036ee7eb

commit edc696a73a7cb07b1aa68792a845a98d036ee7eb
Author: José Bollo <jobol@nonadev.net>
Date:   Tue Mar 8 09:58:16 2022 +0100

    libio: Ensure output buffer for wchars (bug #28828)

    The _IO_wfile_overflow does not check if the write pointer for wide
    data is valid before access, different than _IO_file_overflow.  This
    leads to crash on some cases, as described by bug 28828.

    The minimal sequence to produce the crash was:

      #include <stdio.h>
      #include <wchar.h>
      int main (int ac, char **av)
      {
        setvbuf (stdout, NULL, _IOLBF, 0);
        fgetwc (stdin);
        fputwc (10, stdout); /*CRASH HERE!*/
        return 0;
      }

    The "fgetwc(stdin);" is necessary since it triggers the bug by setting
    the flag _IO_CURRENTLY_PUTTING on stdout indirectly (file wfileops.c,
    function _IO_wfile_underflow, line 213).

    Signed-off-by: Jose Bollo <jobol@nonadev.net>

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Glibc-bugs mailing list