[PATCH] iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module
Adhemerval Zanella Netto
adhemerval.zanella@linaro.org
Fri Nov 28 12:18:45 GMT 2025
On 28/11/25 08:13, Florian Weimer wrote:
> The expression inptr + 1 can technically be invalid: if inptr == inend,
> inptr may point one element past the end of an array.
LGTM, thanks.
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
>
> ---
> iconvdata/ansi_x3.110.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c
> index c5506b13b8..94e6e6b745 100644
> --- a/iconvdata/ansi_x3.110.c
> +++ b/iconvdata/ansi_x3.110.c
> @@ -407,7 +407,7 @@ static const char from_ucs4[][2] =
> is also available. */ \
> uint32_t ch2; \
> \
> - if (inptr + 1 >= inend) \
> + if (inend - inptr <= 1) \
> { \
> /* The second character is not available. */ \
> result = __GCONV_INCOMPLETE_INPUT; \
>
> base-commit: 15de57024611ed6e668acbc440c5e360b0543374
>
More information about the Libc-alpha
mailing list