CVE-2025-0395: fix underallocation of abort_msg_s struct
Resolves: RHEL-75938
This commit is contained in:
parent
835c6731c5
commit
38cc5f2c2b
54
glibc-RHEL-75938.patch
Normal file
54
glibc-RHEL-75938.patch
Normal file
@ -0,0 +1,54 @@
|
||||
commit 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578
|
||||
Author: Siddhesh Poyarekar <siddhesh@sourceware.org>
|
||||
Date: Tue Jan 21 16:11:06 2025 -0500
|
||||
|
||||
Fix underallocation of abort_msg_s struct (CVE-2025-0395)
|
||||
|
||||
Include the space needed to store the length of the message itself, in
|
||||
addition to the message string. This resolves BZ #32582.
|
||||
|
||||
Signed-off-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
|
||||
Reviewed: Adhemerval Zanella <adhemerval.zanella@linaro.org>
|
||||
|
||||
diff -Nrup a/assert/assert.c b/assert/assert.c
|
||||
--- a/assert/assert.c 2025-01-29 14:45:37.480532858 -0500
|
||||
+++ b/assert/assert.c 2025-01-29 14:54:03.824306418 -0500
|
||||
@@ -18,6 +18,7 @@
|
||||
#include <assert.h>
|
||||
#include <atomic.h>
|
||||
#include <ldsodefs.h>
|
||||
+#include <libc-pointer-arith.h>
|
||||
#include <libintl.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
@@ -66,7 +67,8 @@ __assert_fail_base (const char *fmt, con
|
||||
(void) __fxprintf (NULL, "%s", str);
|
||||
(void) fflush (stderr);
|
||||
|
||||
- total = (total + 1 + GLRO(dl_pagesize) - 1) & ~(GLRO(dl_pagesize) - 1);
|
||||
+ total = ALIGN_UP (total + sizeof (struct abort_msg_s) + 1,
|
||||
+ GLRO(dl_pagesize));
|
||||
struct abort_msg_s *buf = __mmap (NULL, total, PROT_READ | PROT_WRITE,
|
||||
MAP_ANON | MAP_PRIVATE, -1, 0);
|
||||
if (__glibc_likely (buf != MAP_FAILED))
|
||||
diff -Nrup a/sysdeps/posix/libc_fatal.c b/sysdeps/posix/libc_fatal.c
|
||||
--- a/sysdeps/posix/libc_fatal.c 2025-01-29 14:45:36.603528055 -0500
|
||||
+++ b/sysdeps/posix/libc_fatal.c 2025-01-29 15:57:20.910535347 -0500
|
||||
@@ -20,6 +20,7 @@
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
#include <ldsodefs.h>
|
||||
+#include <libc-pointer-arith.h>
|
||||
#include <paths.h>
|
||||
#include <stdarg.h>
|
||||
#include <stdbool.h>
|
||||
@@ -123,7 +124,8 @@ __libc_message (const char *fmt, ...)
|
||||
|
||||
WRITEV_FOR_FATAL (fd, iov, nlist, total);
|
||||
|
||||
- total = (total + 1 + GLRO(dl_pagesize) - 1) & ~(GLRO(dl_pagesize) - 1);
|
||||
+ total = ALIGN_UP (total + sizeof (struct abort_msg_s) + 1,
|
||||
+ GLRO(dl_pagesize));
|
||||
struct abort_msg_s *buf = __mmap (NULL, total,
|
||||
PROT_READ | PROT_WRITE,
|
||||
MAP_ANON | MAP_PRIVATE, -1, 0);
|
@ -157,7 +157,7 @@ end \
|
||||
Summary: The GNU libc libraries
|
||||
Name: glibc
|
||||
Version: %{glibcversion}
|
||||
Release: 161%{?dist}
|
||||
Release: 162%{?dist}
|
||||
|
||||
# In general, GPLv2+ is used by programs, LGPLv2+ is used for
|
||||
# libraries.
|
||||
@ -1093,6 +1093,7 @@ Patch785: glibc-RHEL-46761-4.patch
|
||||
Patch786: glibc-RHEL-75810-2.patch
|
||||
Patch787: glibc-RHEL-75810-3.patch
|
||||
Patch788: glibc-RHEL-46761-5.patch
|
||||
Patch789: glibc-RHEL-75938.patch
|
||||
|
||||
##############################################################################
|
||||
# Continued list of core "glibc" package information:
|
||||
@ -3086,6 +3087,9 @@ update_gconv_modules_cache ()
|
||||
%endif
|
||||
|
||||
%changelog
|
||||
* Wed Jan 29 2025 Patsy Griffin <patsy@redhat.com> - 2.34-162
|
||||
- CVE-2025-0395: fix underallocation of abort_msg_s struct (RHEL-75938)
|
||||
|
||||
* Tue Jan 28 2025 Frédéric Bérat <fberat@redhat.com> - 2.34-161
|
||||
- Backport: debug: Add regression tests for BZ 30932 (RHEL-46761)
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user