[PATCH v4.] nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)
Marcus Poller <[email protected]>
| Newsgroups | gmane.comp.lib.glibc.alpha |
|---|---|
| Message-ID | <[email protected]> |
replacing realloc by reallocarray introduces a basic overflow check. (old + count) might still overflow, but since the NSS backend is trusted, we do not consider this to be a valid case. --- v1: https://inbox.sourceware.org/libc-alpha/[email protected]/ v2: iterated on Arjuns and Andreas review comments v3: re-submission to support existing tooling v4: moved from reallocarray to __libc_reallocarray due to a regression found by Adhemerval --- nss/getaddrinfo.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c index 4f6ac3358a..45b7f728a1 100644 --- a/nss/getaddrinfo.c +++ b/nss/getaddrinfo.c @@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct addrinfo *req, int family, array = array->next; } - array = realloc (res->at, (old + count) * sizeof (*array)); + array = __libc_reallocarray (res->at, old + count, sizeof (*array)); if (array == NULL) return false; -- 2.47.3