[glibc/release/2.38/master] iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module

Aurelien Jarno via Glibc-cvs <[email protected]>
Newsgroups gmane.comp.lib.glibc.cvs
Message-ID <[email protected]>
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=d0adddb19aac7e2759436fe4c390f24bc13332ae

commit d0adddb19aac7e2759436fe4c390f24bc13332ae
Author: Florian Weimer <[email protected]>
Date:   Fri Nov 28 11:46:09 2025 +0100

    iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module
    
    The expression inptr + 1 can technically be invalid: if inptr == inend,
    inptr may point one element past the end of an array.
    
    Reviewed-by: Adhemerval Zanella  <[email protected]>
    (cherry picked from commit e98bd0c54d5e296ad1be91b6fe35260c6b87e733)

Diff:
---
 iconvdata/ansi_x3.110.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c
index 45cd08fa69..c9ce763958 100644
--- a/iconvdata/ansi_x3.110.c
+++ b/iconvdata/ansi_x3.110.c
@@ -407,7 +407,7 @@ static const char from_ucs4[][2] =
 	   is also available.  */					      \
 	uint32_t ch2;							      \
 									      \
-	if (inptr + 1 >= inend)						      \
+	if (inend - inptr <= 1)						      \
 	  {								      \
 	    /* The second character is not available.  */		      \
 	    result = __GCONV_INCOMPLETE_INPUT;				      \
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.