[PATCH v3] Fix FORTIFY_SOURCE false positive
Florian Weimer
fweimer@redhat.com
Sun Feb 2 19:15:51 GMT 2025
* Volker Weißmann:
> When -D_FORTIFY_SOURCE=2 was given during compilation,
> sprintf and similar functions will check if their
> first argument is in read-only memory and exit with
> *** %n in writable segment detected ***
> otherwise. To check if the memory is read-only, glibc
> reads frpm the file "/proc/self/maps". If opening this
> file fails due to too many open files (EMFILE), glibc
> will now ignore this error.
>
> Fixes [BZ #30932]
>
> Signed-off-by: Volker Weißmann <volker.weissmann@gmx.de>
> ---
> sysdeps/unix/sysv/linux/readonly-area.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/sysdeps/unix/sysv/linux/readonly-area.c b/sysdeps/unix/sysv/linux/readonly-area.c
> index edc68873f6..ba32372ebb 100644
> --- a/sysdeps/unix/sysv/linux/readonly-area.c
> +++ b/sysdeps/unix/sysv/linux/readonly-area.c
> @@ -42,7 +42,9 @@ __readonly_area (const char *ptr, size_t size)
> to the /proc filesystem if it is set[ug]id. There has
> been no willingness to change this in the kernel so
> far. */
> - || errno == EACCES)
> + || errno == EACCES
> + /* Process has reached the maximum number of open files. */
> + || errno == EMFILE)
> return 1;
> return -1;
> }
For SUID binaries, EMFILE can be attacker-controlled, so this
effectively disables the %n hardening in printf-style functions for some
of those programs.
I think this should use _dl_find_object prior to using /proc/self/maps,
and change behavior for non-SUID programs only.
Thanks,
Florian
More information about the Libc-alpha
mailing list