[PATCH v4.] nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)
Adhemerval Zanella Netto
adhemerval.zanella@linaro.org
Fri Aug 7 17:28:29 GMT 2026
This version looks ok to me.
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
On 06/07/26 09:47, Andreas K. Huettel wrote:
> OK for the release with a R-B
>
> Am Montag, 6. Juli 2026, 17:37:32 Japanische Normalzeit schrieb Marcus Poller:
>> replacing realloc by reallocarray introduces a basic overflow check.
>> (old + count) might still overflow, but since the NSS backend is trusted,
>> we do not consider this to be a valid case.
>> ---
>> v1: https://inbox.sourceware.org/libc-alpha/77a01db3-5619-48b8-9682-85f11cc472bc@crystaldown.de/
>> v2: iterated on Arjuns and Andreas review comments
>> v3: re-submission to support existing tooling
>> v4: moved from reallocarray to __libc_reallocarray due to a regression found by Adhemerval
>> ---
>> nss/getaddrinfo.c | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c
>> index 4f6ac3358a..45b7f728a1 100644
>> --- a/nss/getaddrinfo.c
>> +++ b/nss/getaddrinfo.c
>> @@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct addrinfo *req, int family,
>> array = array->next;
>> }
>>
>> - array = realloc (res->at, (old + count) * sizeof (*array));
>> + array = __libc_reallocarray (res->at, old + count, sizeof (*array));
>>
>> if (array == NULL)
>> return false;
>>
>
>
More information about the Libc-alpha
mailing list