[PATCH v4.] nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)

Andreas K. Huettel dilfridge@gentoo.org
Mon Jul 6 12:47:01 GMT 2026


OK for the release with a R-B

Am Montag, 6. Juli 2026, 17:37:32 Japanische Normalzeit schrieb Marcus Poller:
> replacing realloc by reallocarray introduces a basic overflow check.
> (old + count) might still overflow, but since the NSS backend is trusted,
> we do not consider this to be a valid case.
> ---
> v1: https://inbox.sourceware.org/libc-alpha/77a01db3-5619-48b8-9682-85f11cc472bc@crystaldown.de/
> v2: iterated on Arjuns and Andreas review comments
> v3: re-submission to support existing tooling
> v4: moved from reallocarray to __libc_reallocarray due to a regression found by Adhemerval
> ---
>  nss/getaddrinfo.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c
> index 4f6ac3358a..45b7f728a1 100644
> --- a/nss/getaddrinfo.c
> +++ b/nss/getaddrinfo.c
> @@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct addrinfo *req, int family,
>        array = array->next;
>      }
>  
> -  array = realloc (res->at, (old + count) * sizeof (*array));
> +  array = __libc_reallocarray (res->at, old + count, sizeof (*array));
>  
>    if (array == NULL)
>      return false;
> 


-- 
PD Dr. Andreas K. Hüttel
dilfridge@gentoo.org
Gentoo Linux developer 
(council, comrel, toolchain, base-system, perl, libreoffice)
https://wiki.gentoo.org/wiki/User:Dilfridge
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 870 bytes
Desc: This is a digitally signed message part.
URL: <https://sourceware.org/pipermail/libc-alpha/attachments/20260706/b75f2595/attachment.sig>


More information about the Libc-alpha mailing list