[PATCH] Fix readdir_r with long file names
Florian Weimer
fweimer@redhat.com
Wed Jun 12 12:57:00 GMT 2013
On 06/11/2013 03:13 AM, Rich Felker wrote:
> I think the text should be informative and objective rather than
> dogmatic. It should include the following information:
>
> - On systems where NAME_MAX is not defined, readdir_r cannot be used
> safely, as the interface contract for readdir_r is specified in
> terms of NAME_MAX.
>
> - On systems where NAME_MAX is defined but not enforced for all
> filesystems, there may be directory entries whose names are readable
> by readdir but not readdir_r, and attempts to read such names on
> older versions of glibc may result in exploitable buffer overflows.
>
> - Historically, POSIX does not require readdir to be thread-safe, but
> on most (all?) known recent systems including glibc-based ones, it
> is thread-safe as long as the same directory stream (DIR*) is not
> accessed concurrently from multiple threads.
>
> - Future versions of POSIX will mandate this level of thread-safety
> for the readdir function and mark readdir_r obsolescent.
I tried to incorporate these points into the most recent version. I
will add the bug number to NEWS before the commit. I also changed
readdir_r to use _D_EXACT_NAMLEN, as requested by Roland.
--
Florian Weimer / Red Hat Product Security Team
-------------- next part --------------
A non-text attachment was scrubbed...
Name: readdir_r.patch
Type: text/x-patch
Size: 11293 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20130612/5435b312/attachment.bin>
More information about the Libc-alpha
mailing list