Go to file
Joan Bruguera ca0faa140f misc: Fix rare fortify crash on wchar funcs. [BZ 29030]
If `__glibc_objsize (__o) == (size_t) -1` (i.e. `__o` is unknown size), fortify
checks should pass, and `__whatever_alias` should be called.

Previously, `__glibc_objsize (__o) == (size_t) -1` was explicitly checked, but
on commit a643f60c53, this was moved into `__glibc_safe_or_unknown_len`.

A comment says the -1 case should work as: "The -1 check is redundant because
since it implies that __glibc_safe_len_cond is true.". But this fails when:
* `__s > 1`
* `__osz == -1` (i.e. unknown size at compile time)
* `__l` is big enough
* `__l * __s <= __osz` can be folded to a constant
(I only found this to be true for `mbsrtowcs` and other functions in wchar2.h)

In this case `__l * __s <= __osz` is false, and `__whatever_chk_warn` will be
called by `__glibc_fortify` or `__glibc_fortify_n` and crash the program.

This commit adds the explicit `__osz == -1` check again.
moc crashes on startup due to this, see: https://bugs.archlinux.org/task/74041

Minimal test case (test.c):
    #include <wchar.h>

    int main (void)
    {
        const char *hw = "HelloWorld";
        mbsrtowcs (NULL, &hw, (size_t)-1, NULL);
        return 0;
    }

Build with:
    gcc -O2 -Wp,-D_FORTIFY_SOURCE=2 test.c -o test && ./test

Output:
    *** buffer overflow detected ***: terminated

Fixes: BZ #29030
Signed-off-by: Joan Bruguera <joanbrugueram@gmail.com>
Signed-off-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
(cherry picked from commit 33e03f9cd2)
2022-04-25 18:44:27 +05:30
argp
assert
benchtests tests: use xmalloc to allocate implementation array 2021-07-28 17:45:19 +05:30
bits elf: Issue la_symbind for bind-now (BZ #23734) 2022-04-12 13:32:59 -04:00
catgets Move malloc hooks into a compat DSO 2021-07-22 18:37:59 +05:30
ChangeLog.old Update ChangeLog.old/ChangeLog.23. 2021-08-01 21:33:43 -04:00
conform Use $(pie-default) with conformtest 2021-12-13 20:59:48 +05:30
crypt
csu elf: Add _dl_audit_preinit 2022-04-08 14:18:12 -04:00
ctype
debug misc: Fix rare fortify crash on wchar funcs. [BZ 29030] 2022-04-25 18:44:27 +05:30
dirent
dlfcn elf: Clean up GLIBC_PRIVATE exports of internal libdl symbols 2021-07-07 08:41:24 +02:00
elf Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
gmon
gnulib
grp
gshadow
hesiod
htl htl: Let libc call __pthread_mutex_{,try,un}lock 2021-07-13 23:36:58 +02:00
hurd
iconv iconvconfig: Fix behaviour with --prefix [BZ #28199] 2021-09-13 20:51:04 +05:30
iconvdata gconv: Do not emit spurious NUL character in ISO-2022-JP-3 (bug 28524) 2021-11-04 21:28:43 +01:00
include elf: Issue audit la_objopen for vDSO 2022-04-08 14:18:12 -04:00
inet resolv: Deprecate legacy interfaces in libresolv 2021-07-19 07:55:42 +02:00
intl intl/plural.y: Avoid conflicting declarations of yyerror and yylex 2021-12-23 13:48:04 +01:00
io Make sure that the fortified function conditionals are constant 2022-03-11 20:36:24 +05:30
libio Make sure that the fortified function conditionals are constant 2022-03-11 20:36:24 +05:30
locale localedef: Handle symbolic links when generating locale-archive 2022-03-03 11:58:03 +01:00
localedata Move malloc hooks into a compat DSO 2021-07-22 18:37:59 +05:30
login login: Move libutil into libc 2021-06-30 08:43:37 +02:00
mach
malloc Handle NULL input to malloc_usable_size [BZ #28506] 2021-10-29 14:56:53 +05:30
manual Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
math
mathvec
misc misc: Fix rare fortify crash on wchar funcs. [BZ 29030] 2022-04-25 18:44:27 +05:30
nis nis: nis_local_group may read from __nisgroup[-1] (bug 28075) 2021-07-12 07:58:07 +02:00
nptl nptl: Fix pthread_cancel cancelhandling atomic operations 2022-04-20 12:22:34 -03:00
nptl_db nptl_db: Re-use the ELF-to-abilist converter for ABI checking 2021-06-29 22:17:08 +02:00
nscd Use 64 bit time_t stat internally 2021-06-22 12:09:52 -03:00
nss hurd: Fix arbitrary error code 2022-04-18 17:54:13 +02:00
po po/nl.po: Update Dutch translation. 2021-08-01 20:52:28 -04:00
posix debug: Synchronize feature guards in fortified functions [BZ #28746] 2022-03-11 20:36:24 +05:30
pwd
resolv Move malloc hooks into a compat DSO 2021-07-22 18:37:59 +05:30
resource y2038: Add support for 64-bit time on legacy ABIs 2021-06-15 10:42:11 -03:00
rt librt: add test (bug 28213) 2021-08-16 11:35:35 +05:30
scripts scripts: Add glibcelf.py module 2022-04-22 11:28:57 +02:00
setjmp
shadow
signal y2038: Add support for 64-bit time on legacy ABIs 2021-06-15 10:42:11 -03:00
socket Make sure that the fortified function conditionals are constant 2022-03-11 20:36:24 +05:30
soft-fp soft-fp: Add __extendhfsf2/__extendhfdf2, __truncsfhf2/__truncdfhf2, __eqhf2/__nehf2 2021-07-07 08:01:32 -07:00
stdio-common Move malloc hooks into a compat DSO 2021-07-22 18:37:59 +05:30
stdlib fortify: Fix spurious warning with realpath 2022-03-11 20:36:24 +05:30
string debug: Synchronize feature guards in fortified functions [BZ #28746] 2022-03-11 20:36:24 +05:30
sunrpc CVE-2022-23218: Buffer overflow in sunrpc svcunix_create (bug 28768) 2022-01-17 11:49:25 +01:00
support debug: Synchronize feature guards in fortified functions [BZ #28746] 2022-03-11 20:36:24 +05:30
sysdeps Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
sysvipc Linux: Cleanups after librt move 2021-06-28 09:51:01 +02:00
termios
time timezone: handle truncated timezones from tzcode-2021d and later (BZ #28707) 2022-01-07 10:20:58 +01:00
timezone timezone: test-case for BZ #28707 2022-01-07 10:21:11 +01:00
wcsmbs debug: Synchronize feature guards in fortified functions [BZ #28746] 2022-03-11 20:36:24 +05:30
wctype
.gitattributes
.gitignore
abi-tags
aclocal.m4 configure: Replaced obsolete AC_TRY_COMPILE 2021-06-04 10:16:00 -03:00
config.h.in i386: Remove broken CAN_USE_REGISTER_ASM_EBP (bug 28771) 2022-01-13 15:21:32 +01:00
config.make.in
configure Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
configure.ac Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
COPYING
COPYING.LIB
extra-lib.mk
gen-locales.mk
INSTALL Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
libc-abis
libof-iterator.mk
LICENSES
MAINTAINERS
Makeconfig Run conform/ tests using newly built libc 2021-12-13 09:07:38 +05:30
Makefile Install shared objects under their ABI names 2021-06-28 08:33:57 +02:00
Makefile.help
Makefile.in
Makerules debug: Autogenerate _FORTIFY_SOURCE tests 2022-03-11 20:36:24 +05:30
NEWS Default to --with-default-link=no (bug 25812) 2022-04-22 11:31:14 +02:00
o-iterator.mk
README
Rules Move malloc hooks into a compat DSO 2021-07-22 18:37:59 +05:30
shlib-versions nss: Do not mention NSS test modules in <gnu/lib-names.h> 2022-03-11 11:13:34 +01:00
test-skeleton.c
version.h Prepare for glibc 2.34 release. 2021-08-01 21:24:04 -04:00

This directory contains the sources of the GNU C Library.
See the file "version.h" for what release version you have.

The GNU C Library is the standard system C library for all GNU systems,
and is an important part of what makes up a GNU system.  It provides the
system API for all programs written in C and C-compatible languages such
as C++ and Objective C; the runtime facilities of other programming
languages use the C library to access the underlying operating system.

In GNU/Linux systems, the C library works with the Linux kernel to
implement the operating system behavior seen by user applications.
In GNU/Hurd systems, it works with a microkernel and Hurd servers.

The GNU C Library implements much of the POSIX.1 functionality in the
GNU/Hurd system, using configurations i[4567]86-*-gnu.

When working with Linux kernels, this version of the GNU C Library
requires Linux kernel version 3.2 or later.

Also note that the shared version of the libgcc_s library must be
installed for the pthread library to work correctly.

The GNU C Library supports these configurations for using Linux kernels:

	aarch64*-*-linux-gnu
	alpha*-*-linux-gnu
	arc*-*-linux-gnu
	arm-*-linux-gnueabi
	csky-*-linux-gnuabiv2
	hppa-*-linux-gnu
	i[4567]86-*-linux-gnu
	x86_64-*-linux-gnu	Can build either x86_64 or x32
	ia64-*-linux-gnu
	m68k-*-linux-gnu
	microblaze*-*-linux-gnu
	mips-*-linux-gnu
	mips64-*-linux-gnu
	powerpc-*-linux-gnu	Hardware or software floating point, BE only.
	powerpc64*-*-linux-gnu	Big-endian and little-endian.
	s390-*-linux-gnu
	s390x-*-linux-gnu
	riscv32-*-linux-gnu
	riscv64-*-linux-gnu
	sh[34]-*-linux-gnu
	sparc*-*-linux-gnu
	sparc64*-*-linux-gnu

If you are interested in doing a port, please contact the glibc
maintainers; see https://www.gnu.org/software/libc/ for more
information.

See the file INSTALL to find out how to configure, build, and install
the GNU C Library.  You might also consider reading the WWW pages for
the C library at https://www.gnu.org/software/libc/.

The GNU C Library is (almost) completely documented by the Texinfo manual
found in the `manual/' subdirectory.  The manual is still being updated
and contains some known errors and omissions; we regret that we do not
have the resources to work on the manual as much as we would like.  For
corrections to the manual, please file a bug in the `manual' component,
following the bug-reporting instructions below.  Please be sure to check
the manual in the current development sources to see if your problem has
already been corrected.

Please see https://www.gnu.org/software/libc/bugs.html for bug reporting
information.  We are now using the Bugzilla system to track all bug reports.
This web page gives detailed information on how to report bugs properly.

The GNU C Library is free software.  See the file COPYING.LIB for copying
conditions, and LICENSES for notices about a few contributions that require
these additional notices to be distributed.  License copyright years may be
listed using range notation, e.g., 1996-2015, indicating that every year in
the range, inclusive, is a copyrightable year that would otherwise be listed
individually.