[PATCH v4.] nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)

Marcus Poller <[email protected]>
Newsgroups gmane.comp.lib.glibc.alpha
Message-ID <[email protected]>
replacing realloc by reallocarray introduces a basic overflow check.
(old + count) might still overflow, but since the NSS backend is trusted,
we do not consider this to be a valid case.
---
v1: https://inbox.sourceware.org/libc-alpha/[email protected]/
v2: iterated on Arjuns and Andreas review comments
v3: re-submission to support existing tooling
v4: moved from reallocarray to __libc_reallocarray due to a regression found by Adhemerval
---
 nss/getaddrinfo.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c
index 4f6ac3358a..45b7f728a1 100644
--- a/nss/getaddrinfo.c
+++ b/nss/getaddrinfo.c
@@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct addrinfo *req, int family,
       array = array->next;
     }
 
-  array = realloc (res->at, (old + count) * sizeof (*array));
+  array = __libc_reallocarray (res->at, old + count, sizeof (*array));
 
   if (array == NULL)
     return false;
-- 
2.47.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.