[PATCH] CVE-2016-4429: sunrpc: Do not use alloca in clntudp_call [BZ #20112]
Florian Weimer
fweimer@redhat.com
Thu May 19 12:11:00 GMT 2016
On 05/19/2016 01:53 PM, Andreas Schwab wrote:
> fweimer@redhat.com (Florian Weimer) writes:
>
>> The call is technically in a loop, and under certain circumstances
>> (which are quite difficult to reproduce in a test case), alloca
>> can be invoked repeatedly during a single call to clntudp_call.
>> As a result, the available stack space can be exhausted (even
>> though individual alloca sizes are bounded implicitly by what
>> can fit into a UDP packet, as a side effect of the earlier
>> successful send operation).
>
> If you use a VLA you can avoid that.
It's still a maintenance hazard for libtirpc because they might
eventually support IPv6 jumbograms, which won't fit on the stack.
Florian
More information about the Libc-alpha
mailing list