[PATCH v6] libio: Fix CVE-2026-18374 heap buffer overflow in ccs= handling
Florian Weimer
fweimer@redhat.com
Fri Sep 4 09:44:38 GMT 2026
* Florian Weimer:
> From: 손동균/Process & Infra Lab(SR)/삼성전자 <dongkyun.s@samsung.com>
>
> When fopen() is called with a ,ccs= parameter whose value becomes empty
> after strip(), the code must reject it with EINVAL instead of attempting
> to use it. The original upstr() fallback could read past the ',' delimiter
> and cause a heap buffer overflow.
>
> The fix checks if the charset specification is empty after strip() and
> returns EINVAL immediately, preventing the overflow and following the
> approach described in BZ #34574.
>
> CVE-2026-18374 - CVSS 4.9 (AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
>
> Reported-by: AISLE in partnership with Red Hat
> Signed-off-by: Dongkyun Son <dongkyun.s@samsung.com>
>
> ---
> v6: Resend as UTF-8, with corrected patch.
> libio/fileops.c | 12 +++++++-----
> 1 file changed, 7 insertions(+), 5 deletions(-)
>
> diff --git a/libio/fileops.c b/libio/fileops.c
> index 9348d7c3a1..5a249725ee 100644
> --- a/libio/fileops.c
> +++ b/libio/fileops.c
> @@ -355,12 +355,14 @@ _IO_new_file_fopen (FILE *fp, const char *filename, const char *mode,
> *((char *) __mempcpy (ccs, cs + 5, endp - (cs + 5))) = '\0';
> strip (ccs, ccs);
>
> - if (__wcsmbs_named_conv (&fcts, ccs[2] == '\0'
> - ? upstr (ccs, cs + 5) : ccs) != 0)
> + /* After stripping, ccs[2] == '\0' means the charset name is empty.
> + This is not a valid charset and would cause problems downstream.
> + Reject it with EINVAL (BZ #34574, CVE-2026-18374). */
> + if (ccs[2] == '\0' || __wcsmbs_named_conv (&fcts, ccs) != 0)
> {
> - /* Something went wrong, we cannot load the conversion modules.
> - This means we cannot proceed since the user explicitly asked
> - for these. */
> + /* Either the charset name is empty after strip(), or conversion
> + modules cannot be loaded. This means we cannot proceed since
> + the user explicitly asked for character conversion. */
> (void) _IO_file_close_it (fp);
> free (ccs);
> __set_errno (EINVAL);
>
> base-commit: e1643c8df34ee38eedb48dad108f56c18f895aca
Would you please confirm that the formatting is correct?
Thanks,
Florian
More information about the Libc-alpha
mailing list