[PATCH] malloc: Make sure tcache_key is not 0

Samuel Thibault samuel.thibault@ens-lyon.org
Wed Jul 30 00:01:30 GMT 2025


Othersize even if tcache_double_free_verify sets e->key to 0 before
calling __libc_free, it gets called again by __libc_free, thus looping
indefinitely.

Fixes: c968fe50628db74b52124d863cd828225a1d305c ("malloc: Use tailcalls in __libc_free")
---
 malloc/malloc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/malloc/malloc.c b/malloc/malloc.c
index 5ca390cc22..970717eb28 100644
--- a/malloc/malloc.c
+++ b/malloc/malloc.c
@@ -3152,6 +3152,9 @@ tcache_key_initialize (void)
   if (__getrandom_nocancel_nostatus_direct (&tcache_key, sizeof(tcache_key),
 					    GRND_NONBLOCK)
       != sizeof (tcache_key))
+    tcache_key = 0;
+
+  while (tcache_key == 0)
     {
       tcache_key = random_bits ();
 #if __WORDSIZE == 64
-- 
2.47.2



More information about the Libc-alpha mailing list