bug#78880: od Heap-buffer overflow

Pádraig Brady <[email protected]>
Newsgroups gmane.comp.gnu.core-utils.bugs
Message-ID <[email protected]>
On 30/06/2025 01:25, Paul Eggert wrote:
> On 2025-06-29 12:59, Pádraig Brady wrote:
>> I've manually suppressed that error instance in our coverity instance.
> 
> Maybe the change I just installed removed the need for that manual
> suppression?

Indeed it does.
I checked with ./configure utils_cv_ieee_16_bit_supported=no
and also installed the following to avoid issues with that configuration:

I also installed a syntax-check tweak to use quotef() rather than quotearg_colon().

thanks!
Padraig

commit 87dcd447b165fee248ead5d15a8d2ea3eeaed15e (HEAD -> master)
Author: Pádraig Brady <[email protected]>
Date:   Mon Jun 30 14:25:56 2025 +0100

     od: reinstate half float validation check

     Reinstate check removed in commit 56aa549a0 so that we
     disallow -f2 when configured with utils_cv_ieee_16_bit_supported=no.
     Otherwise the output routines will consume floats,
     i.e. 4 bytes at a time.  Without this extra check
     the tests/od/od-endian.sh will fail with this configuration.

     * src/od.c (decode_one_format): Reinstate the explicit check
     for this configuration edge case.

diff --git a/src/od.c b/src/od.c
index 700470b85..24e981cb0 100644
--- a/src/od.c
+++ b/src/od.c
@@ -871,7 +871,9 @@ decode_one_format (char const *s_orig, char const *s, char const **next,
            else
              {
                if (ARRAY_CARDINALITY (fp_type_size) <= size
-                  || fp_type_size[size] == NO_SIZE)
+                  || fp_type_size[size] == NO_SIZE
+                  || (! FLOAT16_SUPPORTED && BF16_SUPPORTED
+                      && size == sizeof (bfloat16)))
                  {
                    error (0, 0,
                           _("invalid type string %s;\n"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.