[patch] Fix BZ 18036 buffer overflow (read past end of buffer) in internal_fnmatch=>end_pattern

Paul Pluzhnikov ppluzhnikov@gmail.com
Mon Mar 2 16:54:00 GMT 2015


On Mon, Mar 2, 2015 at 5:18 AM, Florian Weimer <fweimer@redhat.com> wrote:

> Okay to commit if you have checked that the test case actually tests the
> bug.  Thanks.

I missed the "make it fail" step, and it actually didn't :-(

Fixed. Thanks,

2015-03-02  Paul Pluzhnikov  <ppluzhnikov@google.com>

        [BZ #18036]
        * posix/fnmatch_loop.c (END): Detect invalid pattern.
        * posix/tst-fnmatch3.c (do_bz18036): Add test case.

-- 
Paul Pluzhnikov
-------------- next part --------------
diff --git a/posix/fnmatch_loop.c b/posix/fnmatch_loop.c
index 72c5d8f..f46c9df 100644
--- a/posix/fnmatch_loop.c
+++ b/posix/fnmatch_loop.c
@@ -1036,7 +1036,12 @@ END (const CHAR *pattern)
       }
     else if ((*p == L('?') || *p == L('*') || *p == L('+') || *p == L('@')
 	      || *p == L('!')) && p[1] == L('('))
-      p = END (p + 1);
+      {
+	p = END (p + 1);
+	if (*p == L('\0'))
+	  /* This is an invalid pattern.  */
+	  return pattern;
+      }
     else if (*p == L(')'))
       break;
 
diff --git a/posix/tst-fnmatch3.c b/posix/tst-fnmatch3.c
index 75bc00a..fdf9934 100644
--- a/posix/tst-fnmatch3.c
+++ b/posix/tst-fnmatch3.c
@@ -17,6 +17,26 @@
    <http://www.gnu.org/licenses/>.  */
 
 #include <fnmatch.h>
+#include <sys/mman.h>
+#include <string.h>
+#include <unistd.h>
+
+int
+do_bz18036 (void)
+{
+  const char p[] = "**(!()";
+  const int pagesize = getpagesize ();
+
+  char *pattern = mmap (0, 2 * pagesize, PROT_READ|PROT_WRITE,
+                        MAP_PRIVATE|MAP_ANONYMOUS, -1, 0);
+  if (pattern == MAP_FAILED) return 1;
+
+  mprotect (pattern + pagesize, pagesize, PROT_NONE);
+  memset (pattern, ' ', pagesize);
+  strcpy (pattern, p);
+
+  return fnmatch (pattern, p, FNM_EXTMATCH);
+}
 
 int
 do_test (void)
@@ -25,7 +45,7 @@ do_test (void)
     return 1;
   if (fnmatch ("[a[.\0.]]", "a", 0) != FNM_NOMATCH)
     return 1;
-  return 0;
+  return do_bz18036 ();
 }
 
 #define TEST_FUNCTION do_test ()


More information about the Libc-alpha mailing list