nss: introduce signed integer overflow check in malloc

Marcus Poller h-glibcdev@crystaldown.de
Sat Jun 20 08:13:50 GMT 2026


Thank you Arjun and Andreas for the detailed feedback, I have taken it 
into account and would like to submit revision 2:

nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)

replacing realloc by reallocarray introduces a basic overflow check.
(old + count) might still overflow, but since the NSS backend is trusted,
we do not consider this to be a valid case.
---
  nss/getaddrinfo.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c
index 4f6ac3358a..b6ac0b2dcc 100644
--- a/nss/getaddrinfo.c
+++ b/nss/getaddrinfo.c
@@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct 
addrinfo *req, int family,
        array = array->next;
      }

-  array = realloc (res->at, (old + count) * sizeof (*array));
+  array = reallocarray (res->at, old + count, sizeof (*array));

    if (array == NULL)
      return false;
-- 
2.47.3




More information about the Libc-alpha mailing list