[PATCH v2 10/14] stdio-common: Fix bad NaN crash in scanf input specifier tests [BZ #32857]
Adhemerval Zanella Netto
adhemerval.zanella@linaro.org
Fri Aug 15 13:03:58 GMT 2025
On 05/06/25 14:59, Maciej W. Rozycki wrote:
> From: Maciej W. Rozycki <macro@redhat.com>
>
> Fix a null pointer dereference causing a crash in 'read_real' when the
> terminating null character is written for use with the subsequent call
> to 'nan' for invalid NaN reference input, such as:
>
> %a:nan:1:3:nanny:
>
> by moving all the 'n-char-sequence' handling under the check for the
> opening parenthesis.
>
> No test case added as it's a test case issue in the first place.
> ---
> Changes from v1 (formerly 11/15):
>
> - Factor in the removal of former 09/15.
LGTM, thanks.
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
> ---
> stdio-common/tst-scanf-format-real.h | 64 ++++++++++++++++++-----------------
> 1 file changed, 33 insertions(+), 31 deletions(-)
>
> glibc-tst-scanf-format-all-bz32857-real-nan-arg-fix.diff
> Index: glibc/stdio-common/tst-scanf-format-real.h
> ===================================================================
> --- glibc.orig/stdio-common/tst-scanf-format-real.h
> +++ glibc/stdio-common/tst-scanf-format-real.h
> @@ -201,41 +201,43 @@ out: \
> goto out; \
> } \
> \
> - size_t seq_size = 0; \
> - char *seq = NULL; \
> - i = 0; \
> if (ch == '(') \
> - while (1) \
> - { \
> - if (i == seq_size) \
> - { \
> - seq_size += SIZE_CHUNK; \
> - seq = xrealloc (seq, seq_size); \
> - } \
> - ch = read_input (); \
> - if (ch == ')') \
> - break; \
> - if (ch != '_' && !isdigit (ch) \
> - && !(ch >= 'A' && ch <= 'Z') \
> - && !(ch >= 'a' && ch <= 'z')) \
> - { \
> - free (seq); \
> - err = ch < 0 ? ch : INPUT_FORMAT; \
> - v = NAN; \
> - goto out; \
> - } \
> - seq[i++] = ch; \
> - } \
> - seq[i] = '\0'; \
> - \
> - ch = read_input (); \
> - if (ch == ':') \
> { \
> - v = m ? -nan (v, seq) : nan (v, seq); \
> + size_t seq_size = 0; \
> + char *seq = NULL; \
> + i = 0; \
> + while (1) \
> + { \
> + if (i == seq_size) \
> + { \
> + seq_size += SIZE_CHUNK; \
> + seq = xrealloc (seq, seq_size); \
> + } \
> + ch = read_input (); \
> + if (ch == ')') \
> + break; \
> + if (ch != '_' && !isdigit (ch) \
> + && !(ch >= 'A' && ch <= 'Z') \
> + && !(ch >= 'a' && ch <= 'z')) \
> + { \
> + free (seq); \
> + err = ch < 0 ? ch : INPUT_FORMAT; \
> + v = NAN; \
> + goto out; \
> + } \
> + seq[i++] = ch; \
> + } \
> + seq[i] = '\0'; \
> + \
> + ch = read_input (); \
> + if (ch == ':') \
> + { \
> + v = m ? -nan (v, seq) : nan (v, seq); \
> + free (seq); \
> + goto out; \
> + } \
> free (seq); \
> - goto out; \
> } \
> - free (seq); \
> } \
> err = ch < 0 ? ch : INPUT_FORMAT; \
> v = NAN; \
More information about the Libc-alpha
mailing list