[glibc/release/2.41/master] stdio-common: Fix buffer overflow in scanf %mc [BZ #34008]
Aurelien Jarno via Glibc-cvs <[email protected]> Tue, 23 Jun 2026 04:38:49 +0000 (GMT)
| Newsgroups | gmane.comp.lib.glibc.cvs |
|---|---|
| Message-ID | <[email protected]> |
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=1a74f82eedaf0987eda1f522121e6a48fac502e7 commit 1a74f82eedaf0987eda1f522121e6a48fac502e7 Author: Rocket Ma <[email protected]> Date: Fri Apr 17 23:48:41 2026 -0700 stdio-common: Fix buffer overflow in scanf %mc [BZ #34008] * stdio-common/vfscanf-internal.c: When enlarging allocated buffer with format %mc or %mC, glibc allocates one byte less, leading to user-controlled one byte overflow. This commit fixes BZ #34008, or CVE-2026-5450. Reviewed-by: Carlos O'Donell <[email protected]> Signed-off-by: Rocket Ma <[email protected]> Reviewed-by: H.J. Lu <[email protected]> (cherry picked from commit 839898777226a3ed88c0859f25ffe712519b4ead) Diff: --- stdio-common/Makefile | 4 ++++ stdio-common/tst-vfscanf-bz34008.c | 48 ++++++++++++++++++++++++++++++++++++++ stdio-common/vfscanf-internal.c | 7 +++--- 3 files changed, 55 insertions(+), 4 deletions(-) diff --git a/stdio-common/Makefile b/stdio-common/Makefile index ac098dcd8a..72c18e5dc1 100644 --- a/stdio-common/Makefile +++ b/stdio-common/Makefile @@ -311,6 +311,7 @@ tests := \ tst-vfprintf-user-type \ tst-vfprintf-width-i18n \ tst-vfprintf-width-prec-alloc \ + tst-vfscanf-bz34008 \ tst-wc-printf \ tstdiomisc \ tstgetln \ @@ -515,6 +516,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \ tst-vfprintf-width-prec-ENV = \ MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so +tst-vfscanf-bz34008-ENV = \ + MALLOC_CHECK_=3 \ + LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so tst-printf-bz25691-ENV = \ MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c new file mode 100644 index 0000000000..48371c8a3d --- /dev/null +++ b/stdio-common/tst-vfscanf-bz34008.c @@ -0,0 +1,48 @@ +/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008) + Copyright (C) 2026 The GNU Toolchain Authors. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + <https://www.gnu.org/licenses/>. */ + +#include "malloc/mcheck.h" +#include <stddef.h> +#include <stdio.h> +#include <string.h> +#include <wchar.h> +#include <stdlib.h> +#include <malloc.h> +#include <support/check.h> + +#define WIDTH 0x410 +#define SCANFSTR "%1040mc" +static int +do_test (void) +{ + mcheck_pedantic (NULL); + char *input = malloc (WIDTH + 1); + TEST_VERIFY (input != NULL); + memset (input, 'A', WIDTH); + input[WIDTH] = '\0'; + + char *buf = NULL; + TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1); + TEST_VERIFY (buf != NULL); + + free (buf); + free (input); + return 0; +} + +#include <support/test-driver.c> diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c index 1ba034d961..fabb0ec874 100644 --- a/stdio-common/vfscanf-internal.c +++ b/stdio-common/vfscanf-internal.c @@ -853,8 +853,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, { /* Enlarge the buffer. */ size_t newsize - = strsize - + (strsize >= width ? width - 1 : strsize); + = strsize + (strsize >= width ? width : strsize); str = (char *) realloc (*strptr, newsize); if (str == NULL) @@ -930,7 +929,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, && wstr == (wchar_t *) *strptr + strsize) { size_t newsize - = strsize + (strsize > width ? width - 1 : strsize); + = strsize + (strsize >= width ? width : strsize); /* Enlarge the buffer. */ wstr = (wchar_t *) realloc (*strptr, newsize * sizeof (wchar_t)); @@ -985,7 +984,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, && wstr == (wchar_t *) *strptr + strsize) { size_t newsize - = strsize + (strsize > width ? width - 1 : strsize); + = strsize + (strsize >= width ? width : strsize); /* Enlarge the buffer. */ wstr = (wchar_t *) realloc (*strptr, newsize * sizeof (wchar_t));