[PATCH v3] nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)
Marcus Poller
h-glibcdev@crystaldown.de
Wed Jun 24 16:00:58 GMT 2026
replacing realloc by reallocarray introduces a basic overflow check.
(old + count) might still overflow, but since the NSS backend is trusted,
we do not consider this to be a valid case.
---
v1: https://inbox.sourceware.org/libc-alpha/77a01db3-5619-48b8-9682-85f11cc472bc@crystaldown.de/
v2: iterated on Arjuns and Andreas review comments
v3: re-submission to support existing tooling
---
nss/getaddrinfo.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c
index 4f6ac3358a..b6ac0b2dcc 100644
--- a/nss/getaddrinfo.c
+++ b/nss/getaddrinfo.c
@@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct addrinfo *req, int family,
array = array->next;
}
- array = realloc (res->at, (old + count) * sizeof (*array));
+ array = reallocarray (res->at, old + count, sizeof (*array));
if (array == NULL)
return false;
--
2.47.3
More information about the Libc-alpha
mailing list