[PATCH v2 09/14] stdio-common: Fix a crash in scanf input specifier tests [BZ #32857]

Adhemerval Zanella Netto adhemerval.zanella@linaro.org
Fri Aug 15 13:02:39 GMT 2025



On 05/06/25 14:59, Maciej W. Rozycki wrote:
> From: Maciej W. Rozycki <macro@redhat.com>
> 
> Fix a null pointer dereference causing a crash in 'read_real' when the 
> terminating null character is written for use with the subsequent call 
> to 'nan' for NaN reference input using null 'n-char-sequence', such as:
> 
> %a:nan():1:5:nan():
> 
> by moving the memory allocation call ahead of the check for the closing 
> parenthesis.
> 
> No test case added as it's a test case issue in the first place.
> ---
> Changes from v1 (formerly 10/15):
> 
> - Factor in the removal of former 09/15.


LGTM, thanks.

Reviewed-by: Adhemerval Zanella  <adhemerval.zanella@linaro.org>


> ---
>  stdio-common/tst-scanf-format-real.h |   10 +++++-----
>  1 file changed, 5 insertions(+), 5 deletions(-)
> 
> glibc-tst-scanf-format-all-bz32857-real-nan-paren-fix.diff
> Index: glibc/stdio-common/tst-scanf-format-real.h
> ===================================================================
> --- glibc.orig/stdio-common/tst-scanf-format-real.h
> +++ glibc/stdio-common/tst-scanf-format-real.h
> @@ -207,6 +207,11 @@ out:									\
>  	if (ch == '(')							\
>  	  while (1)							\
>  	    {								\
> +	      if (i == seq_size)					\
> +		{							\
> +		  seq_size += SIZE_CHUNK;				\
> +		  seq = xrealloc (seq, seq_size);			\
> +		}							\
>  	      ch = read_input ();					\
>  	      if (ch == ')')						\
>  		break;							\
> @@ -219,11 +224,6 @@ out:									\
>  		  v = NAN;						\
>  		  goto out;						\
>  		}							\
> -	      if (i == seq_size)					\
> -		{							\
> -		  seq_size += SIZE_CHUNK;				\
> -		  seq = xrealloc (seq, seq_size);			\
> -		}							\
>  	      seq[i++] = ch;						\
>  	    }								\
>  	seq[i] = '\0';							\



More information about the Libc-alpha mailing list