[PATCH] newlib: Fix null dereference in __call_exitprocs
Yuichi Nakamura
y.512.nakamura@gmail.com
Sat Oct 3 09:29:07 GMT 2026
When newlib is configured with --enable-newlib-reent-small, a plain
atexit() registration does not require struct _on_exit_args. Therefore,
the weak __on_exit_args reference may remain unresolved and
p->_on_exit_args_ptr may be NULL.
Commit 7c7d9cf585d0 ("newlib: copy args for atexit()'ed function before
unlock the mutex") made __call_exitprocs() copy the exit function
metadata before releasing the mutex. However, it dereferences args
unconditionally while doing so. As a result, executing a handler
registered only with atexit() can dereference a null pointer in a
_REENT_SMALL configuration.
Handle a missing argument structure as a plain atexit() entry. This
also preserves the requirement that all metadata used after releasing
the mutex is copied to local variables first.
Fixes: 7c7d9cf585d0 ("newlib: copy args for atexit()'ed function before unlock the mutex")
Signed-off-by: Yuichi Nakamura <y.512.nakamura@gmail.com>
---
newlib/libc/stdlib/__call_atexit.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/newlib/libc/stdlib/__call_atexit.c b/newlib/libc/stdlib/__call_atexit.c
index 15ecda343..81514574d 100644
--- a/newlib/libc/stdlib/__call_atexit.c
+++ b/newlib/libc/stdlib/__call_atexit.c
@@ -116,9 +116,18 @@ __call_exitprocs (int code, void *d)
ind = p->_ind;
- fntypes = args->_fntypes;
- is_cxa = args->_is_cxa;
- fnarg = args->_fnargs[n];
+ if (args)
+ {
+ fntypes = args->_fntypes;
+ is_cxa = args->_is_cxa;
+ fnarg = args->_fnargs[n];
+ }
+ else
+ {
+ fntypes = 0;
+ is_cxa = 0;
+ fnarg = NULL;
+ }
#ifndef __SINGLE_THREAD__
/* Unlock __atexit_recursive_mutex; otherwise, the function fn() may
--
2.43.0
More information about the Newlib
mailing list