[PATCH] iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module
Collin Funk
collin.funk1@gmail.com
Fri Nov 28 18:23:45 GMT 2025
Florian Weimer <fweimer@redhat.com> writes:
> The expression inptr + 1 can technically be invalid: if inptr == inend,
> inptr may point one element past the end of an array.
>
> ---
> iconvdata/ansi_x3.110.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c
> index c5506b13b8..94e6e6b745 100644
> --- a/iconvdata/ansi_x3.110.c
> +++ b/iconvdata/ansi_x3.110.c
> @@ -407,7 +407,7 @@ static const char from_ucs4[][2] =
> is also available. */ \
> uint32_t ch2; \
> \
> - if (inptr + 1 >= inend) \
> + if (inend - inptr <= 1) \
> { \
> /* The second character is not available. */ \
> result = __GCONV_INCOMPLETE_INPUT; \
>
> base-commit: 15de57024611ed6e668acbc440c5e360b0543374
Just curious, was this found with -Wstrict-overflow (I think that is the
right one)? Might be worth mentioning the warning options used in the
commit message if so.
Reviewed-by: Collin Funk <collin.funk1@gmail.com>
Collin
More information about the Libc-alpha
mailing list