[PATCH v2 10/14] stdio-common: Fix bad NaN crash in scanf input specifier tests [BZ #32857]

Adhemerval Zanella Netto adhemerval.zanella@linaro.org
Fri Aug 15 13:03:58 GMT 2025



On 05/06/25 14:59, Maciej W. Rozycki wrote:
> From: Maciej W. Rozycki <macro@redhat.com>
> 
> Fix a null pointer dereference causing a crash in 'read_real' when the 
> terminating null character is written for use with the subsequent call 
> to 'nan' for invalid NaN reference input, such as:
> 
> %a:nan:1:3:nanny:
> 
> by moving all the 'n-char-sequence' handling under the check for the 
> opening parenthesis.
> 
> No test case added as it's a test case issue in the first place.
> ---
> Changes from v1 (formerly 11/15):
> 
> - Factor in the removal of former 09/15.


LGTM, thanks.

Reviewed-by: Adhemerval Zanella  <adhemerval.zanella@linaro.org>

> ---
>  stdio-common/tst-scanf-format-real.h |   64 ++++++++++++++++++-----------------
>  1 file changed, 33 insertions(+), 31 deletions(-)
> 
> glibc-tst-scanf-format-all-bz32857-real-nan-arg-fix.diff
> Index: glibc/stdio-common/tst-scanf-format-real.h
> ===================================================================
> --- glibc.orig/stdio-common/tst-scanf-format-real.h
> +++ glibc/stdio-common/tst-scanf-format-real.h
> @@ -201,41 +201,43 @@ out:									\
>  	    goto out;							\
>  	  }								\
>  									\
> -	size_t seq_size = 0;						\
> -	char *seq = NULL;						\
> -	i = 0;								\
>  	if (ch == '(')							\
> -	  while (1)							\
> -	    {								\
> -	      if (i == seq_size)					\
> -		{							\
> -		  seq_size += SIZE_CHUNK;				\
> -		  seq = xrealloc (seq, seq_size);			\
> -		}							\
> -	      ch = read_input ();					\
> -	      if (ch == ')')						\
> -		break;							\
> -	      if (ch != '_' && !isdigit (ch)				\
> -		  && !(ch >= 'A' && ch <= 'Z')				\
> -		  && !(ch >= 'a' && ch <= 'z'))				\
> -		{							\
> -		  free (seq);						\
> -		  err = ch < 0 ? ch : INPUT_FORMAT;			\
> -		  v = NAN;						\
> -		  goto out;						\
> -		}							\
> -	      seq[i++] = ch;						\
> -	    }								\
> -	seq[i] = '\0';							\
> -									\
> -	ch = read_input ();						\
> -	if (ch == ':')							\
>  	  {								\
> -	    v = m ? -nan (v, seq) : nan (v, seq);			\
> +	    size_t seq_size = 0;					\
> +	    char *seq = NULL;						\
> +	    i = 0;							\
> +	    while (1)							\
> +	      {								\
> +		if (i == seq_size)					\
> +		  {							\
> +		    seq_size += SIZE_CHUNK;				\
> +		    seq = xrealloc (seq, seq_size);			\
> +		  }							\
> +		ch = read_input ();					\
> +		if (ch == ')')						\
> +		  break;						\
> +		if (ch != '_' && !isdigit (ch)				\
> +		    && !(ch >= 'A' && ch <= 'Z')			\
> +		    && !(ch >= 'a' && ch <= 'z'))			\
> +		  {							\
> +		    free (seq);						\
> +		    err = ch < 0 ? ch : INPUT_FORMAT;			\
> +		    v = NAN;						\
> +		    goto out;						\
> +		  }							\
> +		seq[i++] = ch;						\
> +	      }								\
> +	    seq[i] = '\0';						\
> +									\
> +	    ch = read_input ();						\
> +	    if (ch == ':')						\
> +	      {								\
> +		v = m ? -nan (v, seq) : nan (v, seq);			\
> +		free (seq);						\
> +		goto out;						\
> +	      }								\
>  	    free (seq);							\
> -	    goto out;							\
>  	  }								\
> -	free (seq);							\
>        }									\
>        err = ch < 0 ? ch : INPUT_FORMAT;					\
>        v = NAN;								\



More information about the Libc-alpha mailing list