[PATCH] iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module
Florian Weimer
fweimer@redhat.com
Fri Nov 28 11:13:46 GMT 2025
The expression inptr + 1 can technically be invalid: if inptr == inend,
inptr may point one element past the end of an array.
---
iconvdata/ansi_x3.110.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c
index c5506b13b8..94e6e6b745 100644
--- a/iconvdata/ansi_x3.110.c
+++ b/iconvdata/ansi_x3.110.c
@@ -407,7 +407,7 @@ static const char from_ucs4[][2] =
is also available. */ \
uint32_t ch2; \
\
- if (inptr + 1 >= inend) \
+ if (inend - inptr <= 1) \
{ \
/* The second character is not available. */ \
result = __GCONV_INCOMPLETE_INPUT; \
base-commit: 15de57024611ed6e668acbc440c5e360b0543374
More information about the Libc-alpha
mailing list