[PATCH][BZ #14286] Fix integer overflow in vfwprintf.
Ondřej Bílka
neleai@seznam.cz
Mon Oct 21 08:27:00 GMT 2013
Hi,
This is another straightforward bug, that is fixed by adding overflow
check.
OK to commit?
[BZ #14286]
* stdio-common/vfprintf.c: Fix integer overflow.
diff --git a/stdio-common/vfprintf.c b/stdio-common/vfprintf.c
index 8cd7a85..ba6b6d1 100644
--- a/stdio-common/vfprintf.c
+++ b/stdio-common/vfprintf.c
@@ -1067,7 +1067,12 @@ vfprintf (FILE *s, const CHAR_T *format, va_list ap)
/* Allocate dynamically an array which definitely is long \
enough for the wide character version. Each byte in the \
multi-byte string can produce at most one wide character. */ \
- if (__libc_use_alloca (len * sizeof (wchar_t))) \
+ if (len > SIZE_MAX / sizeof (wchar_t)) \
+ { \
+ done = -1; \
+ goto all_done; \
+ } \
+ else if (__libc_use_alloca (len * sizeof (wchar_t))) \
string = (CHAR_T *) alloca (len * sizeof (wchar_t)); \
else if ((string = (CHAR_T *) malloc (len * sizeof (wchar_t))) \
== NULL) \
More information about the Libc-alpha
mailing list