[patch] loadarchive: guard against locale-archive corruption
DJ Delorie
dj@redhat.com
Fri Oct 18 21:21:00 GMT 2019
>From 1c9ebf0296d4dfe32dd856fc6d1932212a0b0175 Mon Sep 17 00:00:00 2001
From: DJ Delorie <dj@redhat.com>
Date: Fri, 18 Oct 2019 17:15:52 -0400
Subject: loadarchive: guard against locale-archive corruption
_nl_load_locale_from_archive() checks for a zero size, but
divides by both (size) and (size-2). Extend the check to
guard against a size of two or less.
Tested by manually corrupting locale-archive and running a program
that calls setlocale() with LOCPATH unset (size is typically very
large).
Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1470124
diff --git a/locale/loadarchive.c b/locale/loadarchive.c
index 981f68d410..b4a73d5c94 100644
--- a/locale/loadarchive.c
+++ b/locale/loadarchive.c
@@ -274,7 +274,7 @@ _nl_load_locale_from_archive (int category, const char **namep)
+ head->namehash_offset);
/* Avoid division by 0 if the file is corrupted. */
- if (__glibc_unlikely (head->namehash_size == 0))
+ if (__glibc_unlikely (head->namehash_size <= 2))
goto close_and_out;
idx = hval % head->namehash_size;
More information about the Libc-alpha
mailing list