CVE-2026-5450: Fix buffer overflow in scanf (RHEL-172710)
Resolves: RHEL-172710
This commit is contained in:
parent
396dbae539
commit
ec99e297ec
126
glibc-RHEL-172710-1.patch
Normal file
126
glibc-RHEL-172710-1.patch
Normal file
@ -0,0 +1,126 @@
|
||||
commit 839898777226a3ed88c0859f25ffe712519b4ead
|
||||
Author: Rocket Ma <marocketbd@gmail.com>
|
||||
Date: Fri Apr 17 23:48:41 2026 -0700
|
||||
|
||||
stdio-common: Fix buffer overflow in scanf %mc [BZ #34008]
|
||||
|
||||
* stdio-common/vfscanf-internal.c: When enlarging allocated buffer with
|
||||
format %mc or %mC, glibc allocates one byte less, leading to
|
||||
user-controlled one byte overflow. This commit fixes BZ #34008, or
|
||||
CVE-2026-5450.
|
||||
|
||||
Reviewed-by: Carlos O'Donell <carlos@redhat.com>
|
||||
Signed-off-by: Rocket Ma <marocketbd@gmail.com>
|
||||
Reviewed-by: H.J. Lu <hjl.tools@gmail.com>
|
||||
|
||||
Conflicts:
|
||||
stdio-common/Makefile
|
||||
(usual test differences)
|
||||
|
||||
diff -Nrup a/stdio-common/Makefile b/stdio-common/Makefile
|
||||
--- a/stdio-common/Makefile 2026-06-16 08:24:01.348860456 -0400
|
||||
+++ b/stdio-common/Makefile 2026-06-16 08:18:22.791126117 -0400
|
||||
@@ -290,6 +290,7 @@ tests := \
|
||||
tst-vfprintf-mbs-prec \
|
||||
tst-vfprintf-user-type \
|
||||
tst-vfprintf-width-prec-alloc \
|
||||
+ tst-vfscanf-bz34008 \
|
||||
tst-wc-printf \
|
||||
tstdiomisc \
|
||||
tstgetln \
|
||||
@@ -441,6 +442,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(
|
||||
tst-vfprintf-width-prec-ENV = \
|
||||
MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \
|
||||
LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
|
||||
+tst-vfscanf-bz34008-ENV = \
|
||||
+ MALLOC_CHECK_=3 \
|
||||
+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
|
||||
tst-printf-bz25691-ENV = \
|
||||
MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \
|
||||
LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
|
||||
diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c
|
||||
new file mode 100644
|
||||
index 0000000000..48371c8a3d
|
||||
--- /dev/null
|
||||
+++ b/stdio-common/tst-vfscanf-bz34008.c
|
||||
@@ -0,0 +1,48 @@
|
||||
+/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008)
|
||||
+ Copyright (C) 2026 The GNU Toolchain Authors.
|
||||
+ This file is part of the GNU C Library.
|
||||
+
|
||||
+ The GNU C Library is free software; you can redistribute it and/or
|
||||
+ modify it under the terms of the GNU Lesser General Public
|
||||
+ License as published by the Free Software Foundation; either
|
||||
+ version 2.1 of the License, or (at your option) any later version.
|
||||
+
|
||||
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ Lesser General Public License for more details.
|
||||
+
|
||||
+ You should have received a copy of the GNU Lesser General Public
|
||||
+ License along with the GNU C Library; if not, see
|
||||
+ <https://www.gnu.org/licenses/>. */
|
||||
+
|
||||
+#include "malloc/mcheck.h"
|
||||
+#include <stddef.h>
|
||||
+#include <stdio.h>
|
||||
+#include <string.h>
|
||||
+#include <wchar.h>
|
||||
+#include <stdlib.h>
|
||||
+#include <malloc.h>
|
||||
+#include <support/check.h>
|
||||
+
|
||||
+#define WIDTH 0x410
|
||||
+#define SCANFSTR "%1040mc"
|
||||
+static int
|
||||
+do_test (void)
|
||||
+{
|
||||
+ mcheck_pedantic (NULL);
|
||||
+ char *input = malloc (WIDTH + 1);
|
||||
+ TEST_VERIFY (input != NULL);
|
||||
+ memset (input, 'A', WIDTH);
|
||||
+ input[WIDTH] = '\0';
|
||||
+
|
||||
+ char *buf = NULL;
|
||||
+ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1);
|
||||
+ TEST_VERIFY (buf != NULL);
|
||||
+
|
||||
+ free (buf);
|
||||
+ free (input);
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#include <support/test-driver.c>
|
||||
diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c
|
||||
index 59fc8208aa..3d11ac261e 100644
|
||||
--- a/stdio-common/vfscanf-internal.c
|
||||
+++ b/stdio-common/vfscanf-internal.c
|
||||
@@ -855,8 +855,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
{
|
||||
/* Enlarge the buffer. */
|
||||
size_t newsize
|
||||
- = strsize
|
||||
- + (strsize >= width ? width - 1 : strsize);
|
||||
+ = strsize + (strsize >= width ? width : strsize);
|
||||
|
||||
str = (char *) realloc (*strptr, newsize);
|
||||
if (str == NULL)
|
||||
@@ -929,7 +928,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
&& wstr == (wchar_t *) *strptr + strsize)
|
||||
{
|
||||
size_t newsize
|
||||
- = strsize + (strsize > width ? width - 1 : strsize);
|
||||
+ = strsize + (strsize >= width ? width : strsize);
|
||||
/* Enlarge the buffer. */
|
||||
wstr = (wchar_t *) realloc (*strptr,
|
||||
newsize * sizeof (wchar_t));
|
||||
@@ -984,7 +983,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
&& wstr == (wchar_t *) *strptr + strsize)
|
||||
{
|
||||
size_t newsize
|
||||
- = strsize + (strsize > width ? width - 1 : strsize);
|
||||
+ = strsize + (strsize >= width ? width : strsize);
|
||||
/* Enlarge the buffer. */
|
||||
wstr = (wchar_t *) realloc (*strptr,
|
||||
newsize * sizeof (wchar_t));
|
||||
80
glibc-RHEL-172710-2.patch
Normal file
80
glibc-RHEL-172710-2.patch
Normal file
@ -0,0 +1,80 @@
|
||||
commit b866ef29773b22a1343ff9084374775114350b78
|
||||
Author: Maciej W. Rozycki <macro@redhat.com>
|
||||
Date: Wed May 27 12:57:10 2026 -0400
|
||||
|
||||
support: Implement 'xfmemopen' for seamless 'fmemopen' use
|
||||
|
||||
Add 'xfmemopen' wrapper for seamless 'fmemopen' use in tests, following
|
||||
'xfopen', 'xfclose', etc., and providing a standardized error reporting
|
||||
facility.
|
||||
|
||||
Reviewed-by: Florian Weimer <fweimer@redhat.com>
|
||||
(cherry picked from commit fe709cc24578ecfd2ff5b07e10e3829fcb55075b)
|
||||
|
||||
Reviewed-by: Carlos O'Donell <carlos@redhat.com>
|
||||
|
||||
Conflicts:
|
||||
support/Makefile
|
||||
(usual test differences)
|
||||
support/xstdio.h
|
||||
(adjust for downstream context difference)
|
||||
|
||||
diff -Nrup a/support/Makefile b/support/Makefile
|
||||
--- a/support/Makefile 2026-06-16 10:34:13.241874132 -0400
|
||||
+++ b/support/Makefile 2026-06-16 10:37:06.085172353 -0400
|
||||
@@ -135,6 +135,7 @@ libsupport-routines = \
|
||||
xfchmod \
|
||||
xfclose \
|
||||
xfdopendir \
|
||||
+ xfmemopen \
|
||||
xfopen \
|
||||
xfork \
|
||||
xfread \
|
||||
diff --git a/support/xfmemopen.c b/support/xfmemopen.c
|
||||
new file mode 100644
|
||||
index 0000000000..f1dbc72c67
|
||||
--- /dev/null
|
||||
+++ b/support/xfmemopen.c
|
||||
@@ -0,0 +1,31 @@
|
||||
+/* fmemopen with error checking.
|
||||
+ Copyright (C) 2025 Free Software Foundation, Inc.
|
||||
+ This file is part of the GNU C Library.
|
||||
+
|
||||
+ The GNU C Library is free software; you can redistribute it and/or
|
||||
+ modify it under the terms of the GNU Lesser General Public
|
||||
+ License as published by the Free Software Foundation; either
|
||||
+ version 2.1 of the License, or (at your option) any later version.
|
||||
+
|
||||
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ Lesser General Public License for more details.
|
||||
+
|
||||
+ You should have received a copy of the GNU Lesser General Public
|
||||
+ License along with the GNU C Library; if not, see
|
||||
+ <https://www.gnu.org/licenses/>. */
|
||||
+
|
||||
+#include <support/xstdio.h>
|
||||
+
|
||||
+#include <support/check.h>
|
||||
+#include <stdlib.h>
|
||||
+
|
||||
+FILE *
|
||||
+xfmemopen (void *mem, size_t len, const char *mode)
|
||||
+{
|
||||
+ FILE *fp = fmemopen (mem, len, mode);
|
||||
+ if (fp == NULL)
|
||||
+ FAIL_EXIT1 ("fmemopen (mode \"%s\"): %m", mode);
|
||||
+ return fp;
|
||||
+}
|
||||
diff -Nrup a/support/xstdio.h b/support/xstdio.h
|
||||
--- a/support/xstdio.h 2026-06-16 10:34:10.450856660 -0400
|
||||
+++ b/support/xstdio.h 2026-06-16 10:39:05.792825780 -0400
|
||||
@@ -26,6 +26,7 @@ __BEGIN_DECLS
|
||||
|
||||
FILE *xfopen (const char *path, const char *mode);
|
||||
void xfclose (FILE *);
|
||||
+FILE *xfmemopen (void *mem, size_t len, const char *mode);
|
||||
void xfread (void *ptr, size_t size, size_t nmemb, FILE *stream);
|
||||
|
||||
/* Read a line from FP, using getline. *BUFFER must be NULL, or a
|
||||
457
glibc-RHEL-172710-3.patch
Normal file
457
glibc-RHEL-172710-3.patch
Normal file
@ -0,0 +1,457 @@
|
||||
commit 97926e9017f3faeaacce9337f1288460f5e6ec7d
|
||||
Author: Maciej W. Rozycki <macro@redhat.com>
|
||||
Date: Wed May 27 12:57:10 2026 -0400
|
||||
|
||||
stdio-common: Reject insufficient character data in scanf [BZ #12701]
|
||||
|
||||
Reject invalid formatted scanf character data with the 'c' conversion
|
||||
where there is not enough input available to satisfy the field width
|
||||
requested. It is required by ISO C that this conversion matches a
|
||||
sequence of characters of exactly the number specified by the field
|
||||
width and it is also already documented as such in our own manual:
|
||||
|
||||
"It reads precisely the next N characters, and fails if it cannot get
|
||||
that many."
|
||||
|
||||
Currently a matching success is instead incorrectly produced where the
|
||||
EOF condition is encountered before the required number of characters
|
||||
has been retrieved, and the characters actually obtained are stored in
|
||||
the buffer provided.
|
||||
|
||||
Add test cases accordingly and remove placeholders from 'c' conversion
|
||||
input data for the existing scanf tests.
|
||||
|
||||
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
|
||||
|
||||
[This is a modified version of commit 2b16c76609, which tests for the
|
||||
old behavior and only includes the test cases, for older branches
|
||||
and downstream backports - DJ]
|
||||
|
||||
Reviewed-by: Carlos O'Donell <carlos@redhat.com>
|
||||
|
||||
Conflicts:
|
||||
localedata/Makefile
|
||||
stdio-common/Makefile
|
||||
(usual test differences)
|
||||
|
||||
diff -Nrup a/localedata/Makefile b/localedata/Makefile
|
||||
--- a/localedata/Makefile 2026-06-16 09:15:19.295653341 -0400
|
||||
+++ b/localedata/Makefile 2026-06-16 09:11:51.111414458 -0400
|
||||
@@ -160,6 +160,7 @@ tests = \
|
||||
bug-iconv-trans \
|
||||
bug-setlocale1 \
|
||||
bug-usesetlocale \
|
||||
+ tst-bz12701-lc \
|
||||
tst-c-utf8-consistency \
|
||||
tst-digits \
|
||||
tst-iconv-math-trans \
|
||||
diff --git a/localedata/tst-bz12701-lc.c b/localedata/tst-bz12701-lc.c
|
||||
new file mode 100644
|
||||
index 0000000000..23c2ab7d2a
|
||||
--- /dev/null
|
||||
+++ b/localedata/tst-bz12701-lc.c
|
||||
@@ -0,0 +1,218 @@
|
||||
+/* Verify scanf field width handling with the 'lc' conversion (BZ #12701).
|
||||
+ Copyright (C) 2025-2026 Free Software Foundation, Inc.
|
||||
+ This file is part of the GNU C Library.
|
||||
+
|
||||
+ The GNU C Library is free software; you can redistribute it and/or
|
||||
+ modify it under the terms of the GNU Lesser General Public
|
||||
+ License as published by the Free Software Foundation; either
|
||||
+ version 2.1 of the License, or (at your option) any later version.
|
||||
+
|
||||
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ Lesser General Public License for more details.
|
||||
+
|
||||
+ You should have received a copy of the GNU Lesser General Public
|
||||
+ License along with the GNU C Library; if not, see
|
||||
+ <https://www.gnu.org/licenses/>. */
|
||||
+
|
||||
+#include <locale.h>
|
||||
+#include <stddef.h>
|
||||
+#include <stdio.h>
|
||||
+#include <string.h>
|
||||
+#include <wchar.h>
|
||||
+
|
||||
+#include <libc-diag.h>
|
||||
+#include <support/check.h>
|
||||
+#include <support/next_to_fault.h>
|
||||
+#include <support/xstdio.h>
|
||||
+
|
||||
+/* Compare character-wise the initial part of the wide character object
|
||||
+ pointed to by WS corresponding to wide characters obtained by the
|
||||
+ conversion of first N bytes of the multibyte character object pointed
|
||||
+ to by S. */
|
||||
+
|
||||
+static int
|
||||
+tst_bz12701_lc_memcmp (const wchar_t *ds, const char *s, size_t n)
|
||||
+{
|
||||
+ size_t nc = mbsnrtowcs (NULL, &s, n, 0, NULL);
|
||||
+
|
||||
+ struct support_next_to_fault ntf;
|
||||
+ ntf = support_next_to_fault_allocate (nc * sizeof (wchar_t));
|
||||
+ wchar_t *ss = (wchar_t *) ntf.buffer;
|
||||
+
|
||||
+ mbsnrtowcs (ss, &s, n, nc, NULL);
|
||||
+ int r = wmemcmp (ds, ss, nc);
|
||||
+
|
||||
+ support_next_to_fault_free (&ntf);
|
||||
+
|
||||
+ return r;
|
||||
+}
|
||||
+
|
||||
+/* Verify various aspects of field width handling, including the data
|
||||
+ obtained, the number of bytes consumed, and the stream position. */
|
||||
+
|
||||
+static int
|
||||
+do_test (void)
|
||||
+{
|
||||
+ if (setlocale (LC_ALL, "pl_PL.UTF-8") == NULL)
|
||||
+ FAIL_EXIT1 ("setlocale (LC_ALL, \"pl_PL.UTF-8\")");
|
||||
+
|
||||
+ /* Part of a tongue-twister in Polish, which says:
|
||||
+ "On a rainy morning cuckoos and warblers, rather than starting
|
||||
+ on earthworms, stuffed themselves fasted with the flesh of cress." */
|
||||
+ static const char s[126] = "Dżdżystym rankiem gżegżółki i piegże, "
|
||||
+ "zamiast wziąć się za dżdżownice, "
|
||||
+ "nażarły się na czczo miąższu rzeżuchy";
|
||||
+
|
||||
+ const char *sp = s;
|
||||
+ size_t nc;
|
||||
+ TEST_VERIFY_EXIT ((nc = mbsnrtowcs (NULL, &sp, sizeof (s), 0, NULL)) == 108);
|
||||
+
|
||||
+ struct support_next_to_fault ntfo, ntfi;
|
||||
+ ntfo = support_next_to_fault_allocate (nc * sizeof (wchar_t));
|
||||
+ ntfi = support_next_to_fault_allocate (sizeof (s));
|
||||
+ wchar_t *e = (wchar_t *) ntfo.buffer + nc;
|
||||
+ char *b = ntfi.buffer;
|
||||
+
|
||||
+ wchar_t *c;
|
||||
+ FILE *f;
|
||||
+ int ic;
|
||||
+ int n;
|
||||
+ int i;
|
||||
+
|
||||
+ memcpy (ntfi.buffer, s, sizeof (s));
|
||||
+
|
||||
+ ic = i = 0;
|
||||
+ f = xfmemopen (b, sizeof (s), "r");
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */
|
||||
+ DIAG_PUSH_NEEDS_COMMENT;
|
||||
+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat");
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%0lc%n", c, &n) == 1);
|
||||
+ DIAG_POP_NEEDS_COMMENT;
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 1;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 2);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 1;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%1lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 1;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 2;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 3);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 2;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 4;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%4lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 4);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 4;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 8;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%8lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 8);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 8;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 16;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%16lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 20);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 16;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 32;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%32lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 38);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 32;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - (nc - ic);
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_COMPARE (fscanf (f, "%64lc%n", c, &n), 1);
|
||||
+ TEST_COMPARE (n , 49);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, sizeof (s) - i) == 0);
|
||||
+
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s));
|
||||
+ TEST_VERIFY_EXIT (feof (f) != 0);
|
||||
+
|
||||
+ xfclose (f);
|
||||
+
|
||||
+ ic = i = 0;
|
||||
+ f = xfmemopen (b, 3, "r");
|
||||
+
|
||||
+ c = e - 2;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 3);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 2;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - (nc - ic);
|
||||
+ TEST_VERIFY_EXIT (feof (f) == 0);
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == EOF);
|
||||
+ TEST_VERIFY_EXIT (n == 3);
|
||||
+
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == 3);
|
||||
+ TEST_VERIFY_EXIT (feof (f) != 0);
|
||||
+
|
||||
+ xfclose (f);
|
||||
+
|
||||
+ ic = i = 0;
|
||||
+ f = xfmemopen (b, 3, "r");
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0);
|
||||
+ ic += 1;
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - (nc - ic);
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 2);
|
||||
+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, 3 - i) == 0);
|
||||
+
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == 3);
|
||||
+ TEST_VERIFY_EXIT (feof (f) != 0);
|
||||
+
|
||||
+ xfclose (f);
|
||||
+
|
||||
+ support_next_to_fault_free (&ntfi);
|
||||
+ support_next_to_fault_free (&ntfo);
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#include <support/test-driver.c>
|
||||
diff -Nrup a/stdio-common/Makefile b/stdio-common/Makefile
|
||||
--- a/stdio-common/Makefile 2026-06-16 09:15:19.320447732 -0400
|
||||
+++ b/stdio-common/Makefile 2026-06-16 09:14:09.814624522 -0400
|
||||
@@ -217,6 +217,7 @@ tests := \
|
||||
tllformat \
|
||||
tst-bz11319 \
|
||||
tst-bz11319-fortify2 \
|
||||
+ tst-bz12701-c \
|
||||
tst-cookie \
|
||||
tst-fclose-devzero \
|
||||
tst-fclose-offset \
|
||||
diff --git a/stdio-common/tst-bz12701-c.c b/stdio-common/tst-bz12701-c.c
|
||||
new file mode 100644
|
||||
index 0000000000..4f3616fbfd
|
||||
--- /dev/null
|
||||
+++ b/stdio-common/tst-bz12701-c.c
|
||||
@@ -0,0 +1,169 @@
|
||||
+/* Verify scanf field width handling with the 'c' conversion (BZ #12701).
|
||||
+ Copyright (C) 2025-2026 Free Software Foundation, Inc.
|
||||
+ This file is part of the GNU C Library.
|
||||
+
|
||||
+ The GNU C Library is free software; you can redistribute it and/or
|
||||
+ modify it under the terms of the GNU Lesser General Public
|
||||
+ License as published by the Free Software Foundation; either
|
||||
+ version 2.1 of the License, or (at your option) any later version.
|
||||
+
|
||||
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ Lesser General Public License for more details.
|
||||
+
|
||||
+ You should have received a copy of the GNU Lesser General Public
|
||||
+ License along with the GNU C Library; if not, see
|
||||
+ <https://www.gnu.org/licenses/>. */
|
||||
+
|
||||
+#include <stdio.h>
|
||||
+#include <string.h>
|
||||
+
|
||||
+#include <libc-diag.h>
|
||||
+#include <support/check.h>
|
||||
+#include <support/next_to_fault.h>
|
||||
+#include <support/xstdio.h>
|
||||
+
|
||||
+/* Verify various aspects of field width handling, including the data
|
||||
+ obtained, the number of bytes consumed, and the stream position. */
|
||||
+
|
||||
+static int
|
||||
+do_test (void)
|
||||
+{
|
||||
+ static const char s[43] = "The quick brown fox jumps over the lazy dog";
|
||||
+ struct support_next_to_fault ntfo, ntfi;
|
||||
+ ntfo = support_next_to_fault_allocate (sizeof (s));
|
||||
+ ntfi = support_next_to_fault_allocate (sizeof (s));
|
||||
+ char *e = ntfo.buffer + sizeof (s);
|
||||
+ char *b = ntfi.buffer;
|
||||
+
|
||||
+ char *c;
|
||||
+ FILE *f;
|
||||
+ int n;
|
||||
+ int i;
|
||||
+
|
||||
+ memcpy (ntfi.buffer, s, sizeof (s));
|
||||
+
|
||||
+ i = 0;
|
||||
+ f = xfmemopen (b, sizeof (s), "r");
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */
|
||||
+ DIAG_PUSH_NEEDS_COMMENT;
|
||||
+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat");
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%0c%n", c, &n) == 1);
|
||||
+ DIAG_POP_NEEDS_COMMENT;
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%1c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 2;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 2);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 4;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%4c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 4);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 8;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%8c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 8);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 16;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%16c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 16);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - (sizeof (s) - i);
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%32c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 10);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, sizeof (s) - i) == 0);
|
||||
+
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s));
|
||||
+ TEST_VERIFY_EXIT (feof (f) != 0);
|
||||
+
|
||||
+ xfclose (f);
|
||||
+
|
||||
+ i = 0;
|
||||
+ f = xfmemopen (b, 3, "r");
|
||||
+
|
||||
+ c = e - 1;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - 2;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 2);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - (3 - i);
|
||||
+ TEST_VERIFY_EXIT (feof (f) == 0);
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == EOF);
|
||||
+ TEST_VERIFY_EXIT (n == 2);
|
||||
+
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (feof (f) != 0);
|
||||
+
|
||||
+ xfclose (f);
|
||||
+
|
||||
+ i = 0;
|
||||
+ f = xfmemopen (b, 3, "r");
|
||||
+
|
||||
+ c = e - 2;
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 2);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0);
|
||||
+ i += n;
|
||||
+
|
||||
+ c = e - (3 - i);
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == i);
|
||||
+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1);
|
||||
+ TEST_VERIFY_EXIT (n == 1);
|
||||
+ TEST_VERIFY_EXIT (memcmp (c, s + i, 3 - i) == 0);
|
||||
+
|
||||
+ TEST_VERIFY_EXIT (ftell (f) == 3);
|
||||
+ TEST_VERIFY_EXIT (feof (f) != 0);
|
||||
+
|
||||
+ xfclose (f);
|
||||
+
|
||||
+ support_next_to_fault_free (&ntfi);
|
||||
+ support_next_to_fault_free (&ntfo);
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#include <support/test-driver.c>
|
||||
193
glibc-RHEL-172710-4.patch
Normal file
193
glibc-RHEL-172710-4.patch
Normal file
@ -0,0 +1,193 @@
|
||||
commit 6cebb0b80fd783e442a8ad27c3f52cde52a9cac7
|
||||
Author: DJ Delorie <dj@redhat.com>
|
||||
Date: Wed May 27 12:57:10 2026 -0400
|
||||
|
||||
stdio-common: Allow partially-filled %mc buffers [BZ #12701]
|
||||
|
||||
This is a backwards-compatible alternative to the main solution to
|
||||
the %mc part of 12701. The allocated buffer is expanded to the
|
||||
requested size and NUL padded, but truncated reads are allowed.
|
||||
|
||||
Reviewed-by: Carlos O'Donell <carlos@redhat.com>
|
||||
|
||||
Conflicts:
|
||||
localedata/Makefile
|
||||
stdio-common/Makefile
|
||||
(usual test differences)
|
||||
|
||||
diff -Nrup a/localedata/Makefile b/localedata/Makefile
|
||||
--- a/localedata/Makefile 2026-06-16 10:00:37.802495527 -0400
|
||||
+++ b/localedata/Makefile 2026-06-16 09:59:09.766677507 -0400
|
||||
@@ -161,6 +161,7 @@ tests = \
|
||||
bug-setlocale1 \
|
||||
bug-usesetlocale \
|
||||
tst-bz12701-lc \
|
||||
+ tst-bz12701-lc2 \
|
||||
tst-c-utf8-consistency \
|
||||
tst-digits \
|
||||
tst-iconv-math-trans \
|
||||
diff --git a/localedata/tst-bz12701-lc2.c b/localedata/tst-bz12701-lc2.c
|
||||
new file mode 100644
|
||||
index 0000000000..b24e86df0b
|
||||
--- /dev/null
|
||||
+++ b/localedata/tst-bz12701-lc2.c
|
||||
@@ -0,0 +1,47 @@
|
||||
+/* Verify scanf memory handling with the 'c' conversion (BZ #12701).
|
||||
+ Copyright (C) 2026 Free Software Foundation, Inc.
|
||||
+ This file is part of the GNU C Library.
|
||||
+
|
||||
+ The GNU C Library is free software; you can redistribute it and/or
|
||||
+ modify it under the terms of the GNU Lesser General Public
|
||||
+ License as published by the Free Software Foundation; either
|
||||
+ version 2.1 of the License, or (at your option) any later version.
|
||||
+
|
||||
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ Lesser General Public License for more details.
|
||||
+
|
||||
+ You should have received a copy of the GNU Lesser General Public
|
||||
+ License along with the GNU C Library; if not, see
|
||||
+ <https://www.gnu.org/licenses/>. */
|
||||
+
|
||||
+#include <stdio.h>
|
||||
+#include <malloc.h>
|
||||
+#include <string.h>
|
||||
+
|
||||
+#include <libc-diag.h>
|
||||
+#include <support/check.h>
|
||||
+#include <support/next_to_fault.h>
|
||||
+#include <support/xstdio.h>
|
||||
+
|
||||
+static int
|
||||
+do_test (void)
|
||||
+{
|
||||
+ wchar_t *c = NULL;
|
||||
+ int i;
|
||||
+
|
||||
+ TEST_VERIFY (sscanf ("1234", "%30mlc", &c) == 1);
|
||||
+
|
||||
+ TEST_VERIFY (c != NULL);
|
||||
+ TEST_COMPARE_BLOB (c, 5 * sizeof (wchar_t),
|
||||
+ L"1234\0", 5 * sizeof (wchar_t));
|
||||
+ for (i = 5; i < 30; i ++)
|
||||
+ TEST_VERIFY (c[i] == L'\0');
|
||||
+
|
||||
+ TEST_VERIFY (malloc_usable_size (c) >= 30 * sizeof(wchar_t));
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#include <support/test-driver.c>
|
||||
diff -Nrup a/stdio-common/Makefile b/stdio-common/Makefile
|
||||
--- a/stdio-common/Makefile 2026-06-16 10:00:37.803143281 -0400
|
||||
+++ b/stdio-common/Makefile 2026-06-16 09:59:54.974421920 -0400
|
||||
@@ -218,6 +218,7 @@ tests := \
|
||||
tst-bz11319 \
|
||||
tst-bz11319-fortify2 \
|
||||
tst-bz12701-c \
|
||||
+ tst-bz12701-c2 \
|
||||
tst-cookie \
|
||||
tst-fclose-devzero \
|
||||
tst-fclose-offset \
|
||||
diff --git a/stdio-common/tst-bz12701-c2.c b/stdio-common/tst-bz12701-c2.c
|
||||
new file mode 100644
|
||||
index 0000000000..5f9ca7c592
|
||||
--- /dev/null
|
||||
+++ b/stdio-common/tst-bz12701-c2.c
|
||||
@@ -0,0 +1,46 @@
|
||||
+/* Verify scanf memory handling with the 'c' conversion (BZ #12701).
|
||||
+ Copyright (C) 2026 Free Software Foundation, Inc.
|
||||
+ This file is part of the GNU C Library.
|
||||
+
|
||||
+ The GNU C Library is free software; you can redistribute it and/or
|
||||
+ modify it under the terms of the GNU Lesser General Public
|
||||
+ License as published by the Free Software Foundation; either
|
||||
+ version 2.1 of the License, or (at your option) any later version.
|
||||
+
|
||||
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ Lesser General Public License for more details.
|
||||
+
|
||||
+ You should have received a copy of the GNU Lesser General Public
|
||||
+ License along with the GNU C Library; if not, see
|
||||
+ <https://www.gnu.org/licenses/>. */
|
||||
+
|
||||
+#include <stdio.h>
|
||||
+#include <malloc.h>
|
||||
+#include <string.h>
|
||||
+
|
||||
+#include <libc-diag.h>
|
||||
+#include <support/check.h>
|
||||
+#include <support/next_to_fault.h>
|
||||
+#include <support/xstdio.h>
|
||||
+
|
||||
+static int
|
||||
+do_test (void)
|
||||
+{
|
||||
+ char *c = NULL;
|
||||
+ int i;
|
||||
+
|
||||
+ TEST_VERIFY (sscanf ("1234", "%30mc", &c) == 1);
|
||||
+
|
||||
+ TEST_VERIFY (c != NULL);
|
||||
+ TEST_COMPARE_BLOB (c, 5, "1234\0", 5);
|
||||
+ for (i = 5; i < 30; i ++)
|
||||
+ TEST_VERIFY (c[i] == '\0');
|
||||
+
|
||||
+ TEST_VERIFY (malloc_usable_size (c) >= 30);
|
||||
+
|
||||
+ return 0;
|
||||
+}
|
||||
+
|
||||
+#include <support/test-driver.c>
|
||||
diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c
|
||||
index 17b5565d0f..90a1886951 100644
|
||||
--- a/stdio-common/vfscanf-internal.c
|
||||
+++ b/stdio-common/vfscanf-internal.c
|
||||
@@ -780,9 +780,9 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
conv_error (); \
|
||||
} while (0)
|
||||
#ifdef COMPILE_WSCANF
|
||||
- STRING_ARG (str, char, 100);
|
||||
+ STRING_ARG (str, char, (width > 0 ? width : 1));
|
||||
#else
|
||||
- STRING_ARG (str, char, (width > 1024 ? 1024 : width));
|
||||
+ STRING_ARG (str, char, (width > 0 ? width : 1));
|
||||
#endif
|
||||
|
||||
c = inchar ();
|
||||
@@ -891,6 +891,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
|
||||
if (!(flags & SUPPRESS))
|
||||
{
|
||||
+ /* If the buffer isn't completely filled, pad it with NULs. */
|
||||
+ if (flags & MALLOC)
|
||||
+ while (width-- > 0)
|
||||
+ *str++ = '\0';
|
||||
+
|
||||
if ((flags & MALLOC) && str - *strptr != strsize)
|
||||
{
|
||||
char *cp = (char *) realloc (*strptr, str - *strptr);
|
||||
@@ -908,7 +913,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
if (width == -1)
|
||||
width = 1;
|
||||
|
||||
- STRING_ARG (wstr, wchar_t, (width > 1024 ? 1024 : width));
|
||||
+ STRING_ARG (wstr, wchar_t, (width > 0 ? width : 1));
|
||||
|
||||
c = inchar ();
|
||||
if (__glibc_unlikely (c == EOF))
|
||||
@@ -1044,6 +1049,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
|
||||
|
||||
if (!(flags & SUPPRESS))
|
||||
{
|
||||
+ /* If the buffer isn't completely filled, pad it with NULs. */
|
||||
+ if (flags & MALLOC)
|
||||
+ while (width-- > 0)
|
||||
+ *wstr++ = L'\0';
|
||||
+
|
||||
if ((flags & MALLOC) && wstr - (wchar_t *) *strptr != strsize)
|
||||
{
|
||||
wchar_t *cp = (wchar_t *) realloc (*strptr,
|
||||
Loading…
Reference in New Issue
Block a user