free(3) const void *

Alejandro Colomar alx@kernel.org
Fri Jan 26 18:40:44 GMT 2024


On Sat, Jan 27, 2024 at 02:36:09AM +0800, Xi Ruoyao wrote:
> On Fri, 2024-01-26 at 19:23 +0100, Alejandro Colomar wrote:
> > So, after Xi's reminder, I'll reformulate my suggestion to
> > 
> > 	[[gnu::access(none)]]
> > 	void free(const void *p);
> 
> It may defeat glibc.malloc.perturb, which will fill the freed buffer
> with some junk bytes to detect UAF more easily.  Without the access
> attribute the compiler will (definitely) read these junk bytes from the
> freed buffer and hopefully make the program fail in a catastrophic way,
> but with the access attribute the compiler may reuse the previously read
> value stored in some registers, causing the UAF slip away.
> 
> And glibc.malloc.perturb is an environment variable set at runtime, so
> we cannot do it via some #if...

Hmmm, interesting.  Then please ignore the patch I sent a moment ago.
:)

Have a lovely night,
Alex

-- 
<https://www.alejandro-colomar.es/>
Looking for a remote C programming job at the moment.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://sourceware.org/pipermail/libc-alpha/attachments/20240126/0c444022/attachment.sig>


More information about the Libc-alpha mailing list