Re: [PATCH v4.] nss: Use reallocarray to prevent integer overflow in getaddrinfo (bug 33977)
Adhemerval Zanella Netto <[email protected]> Fri, 7 Aug 2026 14:28:29 -0300
| Newsgroups | gmane.comp.lib.glibc.alpha |
|---|---|
| Organization | Linaro |
| Message-ID | <[email protected]> |
This version looks ok to me. Reviewed-by: Adhemerval Zanella <[email protected]> On 06/07/26 09:47, Andreas K. Huettel wrote: > OK for the release with a R-B > > Am Montag, 6. Juli 2026, 17:37:32 Japanische Normalzeit schrieb Marcus Poller: >> replacing realloc by reallocarray introduces a basic overflow check. >> (old + count) might still overflow, but since the NSS backend is trusted, >> we do not consider this to be a valid case. >> --- >> v1: https://inbox.sourceware.org/libc-alpha/[email protected]/ >> v2: iterated on Arjuns and Andreas review comments >> v3: re-submission to support existing tooling >> v4: moved from reallocarray to __libc_reallocarray due to a regression found by Adhemerval >> --- >> nss/getaddrinfo.c | 2 +- >> 1 file changed, 1 insertion(+), 1 deletion(-) >> >> diff --git a/nss/getaddrinfo.c b/nss/getaddrinfo.c >> index 4f6ac3358a..45b7f728a1 100644 >> --- a/nss/getaddrinfo.c >> +++ b/nss/getaddrinfo.c >> @@ -234,7 +234,7 @@ convert_hostent_to_gaih_addrtuple (const struct addrinfo *req, int family, >> array = array->next; >> } >> >> - array = realloc (res->at, (old + count) * sizeof (*array)); >> + array = __libc_reallocarray (res->at, old + count, sizeof (*array)); >> >> if (array == NULL) >> return false; >> > >