[PATCH 1/3] posix: Fix wordexp buffer overflow for $* without positional parameters [BZ #34608]

Adhemerval Zanella adhemerval.zanella@linaro.org
Fri Sep 11 16:58:59 GMT 2026


When expanding an unquoted '$*' or '$@', parse_param sizes the buffer
correclty only when there is at least one positional parameter.

A process invoked without positional parameters makes the loop compute
a length of zero, and then the terminating null byte access invalid
memory.

Checked on x86_64-linux-gnu and i686-linux-gnu.

Reported-by: Shamil Abdulaev <ashamil435@gmail.com>
---
 posix/Makefile             |  7 +++++
 posix/tst-wordexp-noargs.c | 64 ++++++++++++++++++++++++++++++++++++++
 posix/wordexp.c            |  3 +-
 3 files changed, 73 insertions(+), 1 deletion(-)
 create mode 100644 posix/tst-wordexp-noargs.c

diff --git a/posix/Makefile b/posix/Makefile
index ae26443ac9b..bbbb5603122 100644
--- a/posix/Makefile
+++ b/posix/Makefile
@@ -332,11 +332,18 @@ tests := \
   tst-wait4 \
   tst-waitid \
   tst-wordexp-append \
+  tst-wordexp-noargs \
   tst-wordexp-nocmd \
   tst-wordexp-reuse \
   tstgetopt \
   # tests
 
+ifeq ($(build-shared),yes)
+tests-mcheck += \
+  tst-wordexp-noargs \
+  # tests-mcheck
+endif
+
 # Test for the glob symbol version that was replaced in glibc 2.27.
 ifeq ($(have-GLIBC_2.26)$(build-shared),yesyes)
 tests += \
diff --git a/posix/tst-wordexp-noargs.c b/posix/tst-wordexp-noargs.c
new file mode 100644
index 00000000000..589028b6767
--- /dev/null
+++ b/posix/tst-wordexp-noargs.c
@@ -0,0 +1,64 @@
+/* Test wordexp expansion of $* or $@ without positional parameters (BZ 34608).
+   Copyright (C) 2026 Free Software Foundation, Inc.
+   This file is part of the GNU C Library.
+
+   The GNU C Library is free software; you can redistribute it and/or
+   modify it under the terms of the GNU Lesser General Public
+   License as published by the Free Software Foundation; either
+   version 2.1 of the License, or (at your option) any later version.
+
+   The GNU C Library is distributed in the hope that it will be useful,
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+   Lesser General Public License for more details.
+
+   You should have received a copy of the GNU Lesser General Public
+   License along with the GNU C Library; if not, see
+   <https://www.gnu.org/licenses/>.  */
+
+/* The testsuite runs this without positional parameters, so there is
+   nothing for $* and $@ below to expand to.  */
+
+#include <wordexp.h>
+
+#include <support/check.h>
+
+static void
+check_no_field (const char *words)
+{
+  wordexp_t we = { 0 };
+
+  TEST_COMPARE (wordexp (words, &we, 0), 0);
+  TEST_COMPARE (we.we_wordc, 0);
+
+  wordfree (&we);
+}
+
+static void
+check_one_field (const char *words, const char *expected)
+{
+  wordexp_t we = { 0 };
+
+  TEST_COMPARE (wordexp (words, &we, 0), 0);
+  TEST_COMPARE (we.we_wordc, 1);
+  TEST_COMPARE_STRING (we.we_wordv[0], expected);
+
+  wordfree (&we);
+}
+
+static int
+do_test (void)
+{
+  /* Both spellings take the same code path when unquoted, and field
+     splitting leaves nothing behind.  */
+  check_no_field ("$*");
+  check_no_field ("$@");
+
+  /* ${#*} and ${#@} report the number of positional parameters.  */
+  check_one_field ("${#*}", "0");
+  check_one_field ("${#@}", "0");
+
+  return 0;
+}
+
+#include <support/test-driver.c>
diff --git a/posix/wordexp.c b/posix/wordexp.c
index 9a49e102eea..0ad005c0f38 100644
--- a/posix/wordexp.c
+++ b/posix/wordexp.c
@@ -1449,7 +1449,8 @@ envsubst:
 	  /* Build up value parameter by parameter (copy them) */
 	  for (p = 1; __libc_argv[p]; ++p)
 	    plist_len += strlen (__libc_argv[p]) + 1; /* for space */
-	  value = malloc (plist_len);
+	  /* Always compute the NULL byte.  */
+	  value = malloc (plist_len + 1);
 	  if (value == NULL)
 	    goto no_space;
 	  end = value;
-- 
2.53.0



More information about the Libc-alpha mailing list