free(3) const void *
Alejandro Colomar
alx@kernel.org
Fri Jan 26 18:40:44 GMT 2024
On Sat, Jan 27, 2024 at 02:36:09AM +0800, Xi Ruoyao wrote:
> On Fri, 2024-01-26 at 19:23 +0100, Alejandro Colomar wrote:
> > So, after Xi's reminder, I'll reformulate my suggestion to
> >
> > [[gnu::access(none)]]
> > void free(const void *p);
>
> It may defeat glibc.malloc.perturb, which will fill the freed buffer
> with some junk bytes to detect UAF more easily. Without the access
> attribute the compiler will (definitely) read these junk bytes from the
> freed buffer and hopefully make the program fail in a catastrophic way,
> but with the access attribute the compiler may reuse the previously read
> value stored in some registers, causing the UAF slip away.
>
> And glibc.malloc.perturb is an environment variable set at runtime, so
> we cannot do it via some #if...
Hmmm, interesting. Then please ignore the patch I sent a moment ago.
:)
Have a lovely night,
Alex
--
<https://www.alejandro-colomar.es/>
Looking for a remote C programming job at the moment.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://sourceware.org/pipermail/libc-alpha/attachments/20240126/0c444022/attachment.sig>
More information about the Libc-alpha
mailing list