[2.26 COMMITTED] Fix crash in resolver on memory allocation failure (bug 23005)
Florian Weimer
fweimer@redhat.com
Mon Jan 1 00:00:00 GMT 2018
From: Andreas Schwab <schwab@suse.de>
(cherry picked from commit f178e59fa5eefbbd37fde040ae8334aa5c857ee1)
2018-03-27 Andreas Schwab <schwab@suse.de>
[BZ #23005]
* resolv/res_send.c (__res_context_send): Return ENOMEM if
allocation of private copy of nsaddr_list fails.
diff --git a/NEWS b/NEWS
index dcbb2b0ff6..4d360a426e 100644
--- a/NEWS
+++ b/NEWS
@@ -118,6 +118,7 @@ The following bugs are resolved with this release:
[22685] powerpc: Fix syscalls during early process initialization
[22715] x86-64: Properly align La_x86_64_retval to VEC_SIZE
[22774] malloc: Integer overflow in malloc (CVE-2018-6551)
+ [23005] resolv: Fix crash in resolver on memory allocation failure
[23024] getlogin_r: return early when linux sentinel value is set
[23037] resolv: Fully initialize struct mmsghdr in send_dg
diff --git a/resolv/res_send.c b/resolv/res_send.c
index 0ca02f9843..83f35f60da 100644
--- a/resolv/res_send.c
+++ b/resolv/res_send.c
@@ -471,6 +471,11 @@ __res_context_send (struct resolv_context *ctx,
'\0',
sizeof (struct sockaddr_in6)
- sizeof (struct sockaddr_in));
+ else
+ {
+ __set_errno (ENOMEM);
+ return -1;
+ }
}
EXT(statp).nscount = statp->nscount;
}
More information about the Libc-stable
mailing list