Re: cooked-mode `wgetch()` stack off-by-one
Thomas Dickey <[email protected]> Thu, 14 May 2026 04:15:41 -0400
| Newsgroups | gmane.comp.lib.ncurses.bugs |
|---|---|
| Message-ID | <[email protected]> |
On Wed, May 13, 2026 at 09:51:11PM -0400, Daniel Anderson wrote: > Good Evening, > > I confirmed a stack overflow by compiling ncurses with ASAN enabled > caused by the fact that wgetch() can write one byte past the stack buffer. > I’d suggest fixing by allocating an extra byte for the terminator char > buf[MAXCOLUMNS + 1]. actually this would be more consistent with the other calls to wgetnstr: rc = wgetnstr(win, buf, MAXCOLUMNS - 1); (thanks) -- Thomas E. Dickey <[email protected]> https://invisible-island.net
signature.asc
(application/pgp-signature, 659 B)
-----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEEGYgtkt2kxADCLA1WzCr0RyFnvgMFAmoFhK0ACgkQzCr0RyFn vgMZvgv/emSnKRw18oIOuC0xs3lcEnttB9YrNh9wMJ5+lvpe3OPK98zoK+HfIZ4+ yc2p2Zt/0jEjfZBLY+PLXBxbUXb6N5KG9lpezGBGwfttII+nlbzI7YKceMLjkkyA 2tyCBRinv0WSeIQs4sk3prssWzLTlsW1Ih/ZZ3bw5oeV0o43noVS4Rps6Es/1hlm 6RwBQh7bGdVmfMChRTqudYTxnv6fHUgrTgKdrH0DzkU0T9LOoZQlScWWCMcbrBaj bIFjIkbH1kclrfbsNEp5dn6pChJ9lT9zD7khdfoNkXPte81UvEV6oC3DPi2wkfOb djdPuZ4e/xcqK1v2eXI5E0/DzwidW4aEChzFLe0z+q4Eolp8GKVjaEa3ff2NlVvn Uq8JnEF6f9DLrrluU78OM+OfpPXXcXEkVLkZPBSSrvHCdn5BDQn5vK8mFCkUgDHX CuyJOtcWg2Nod0CUKxmzTAw4vDVJsM4wVw+lzP6uQTKbKOwX5ycdQo9g8RkwTTFf WSvverv0 =534z -----END PGP SIGNATURE-----