[PATCH] newlib: Fix null dereference in __call_exitprocs

Yuichi Nakamura y.512.nakamura@gmail.com
Sat Oct 3 09:29:07 GMT 2026


When newlib is configured with --enable-newlib-reent-small, a plain
atexit() registration does not require struct _on_exit_args.  Therefore,
the weak __on_exit_args reference may remain unresolved and
p->_on_exit_args_ptr may be NULL.

Commit 7c7d9cf585d0 ("newlib: copy args for atexit()'ed function before
unlock the mutex") made __call_exitprocs() copy the exit function
metadata before releasing the mutex.  However, it dereferences args
unconditionally while doing so.  As a result, executing a handler
registered only with atexit() can dereference a null pointer in a
_REENT_SMALL configuration.

Handle a missing argument structure as a plain atexit() entry.  This
also preserves the requirement that all metadata used after releasing
the mutex is copied to local variables first.

Fixes: 7c7d9cf585d0 ("newlib: copy args for atexit()'ed function before unlock the mutex")
Signed-off-by: Yuichi Nakamura <y.512.nakamura@gmail.com>
---
 newlib/libc/stdlib/__call_atexit.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/newlib/libc/stdlib/__call_atexit.c b/newlib/libc/stdlib/__call_atexit.c
index 15ecda343..81514574d 100644
--- a/newlib/libc/stdlib/__call_atexit.c
+++ b/newlib/libc/stdlib/__call_atexit.c
@@ -116,9 +116,18 @@ __call_exitprocs (int code, void *d)
 
 	  ind = p->_ind;
 
-	  fntypes = args->_fntypes;
-	  is_cxa = args->_is_cxa;
-	  fnarg = args->_fnargs[n];
+	  if (args)
+	    {
+	      fntypes = args->_fntypes;
+	      is_cxa = args->_is_cxa;
+	      fnarg = args->_fnargs[n];
+	    }
+	  else
+	    {
+	      fntypes = 0;
+	      is_cxa = 0;
+	      fnarg = NULL;
+	    }
 
 #ifndef __SINGLE_THREAD__
 	  /* Unlock __atexit_recursive_mutex; otherwise, the function fn() may
-- 
2.43.0



More information about the Newlib mailing list