Re: [PATCH v2] posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368)

Adhemerval Zanella Netto <[email protected]>
Newsgroups gmane.comp.lib.glibc.alpha
Organization Linaro
Message-ID <[email protected]>

On 12/08/26 11:10, Andreas Schwab wrote:
> On Jul 13 2026, Adhemerval Zanella wrote:
> 
>> @@ -2258,6 +2265,23 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags)
>>  	  pwordexp->we_offs = 0;
>>  	}
>>      }
>> +  else if (pwordexp->we_wordv != NULL)
>> +    {
>> +      /* WRDE_APPEND with an existing word list: duplicate the array so that
>> +	 realloc during parsing does not invalidate the caller's pointer.  The
>> +	 strings themselves are shared.  */
>> +      size_t num_p;
>> +      char **dup;
>> +      if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p)
>> +	  || INT_ADD_WRAPV (num_p, 1, &num_p))
>> +	return WRDE_NOSPACE;
> 
> This can never happen, since it is exactly the size of the array to
> duplicate.
> 

Right, WRDE_APPEND contract with a non-NULL we_wordv should always come from 
previous successful wordexp call.  I think I got too defensive here, I will send
a cleanup to simplify this.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.