mirror of
git://sourceware.org/git/glibc.git
synced 2026-09-08 23:58:31 +08:00
libio: Fix CVE-2026-18374 heap buffer overflow in ccs= handling
When fopen() is called with a ,ccs= parameter whose value becomes empty after strip(), the code must reject it with EINVAL instead of attempting to use it. The original upstr() fallback could read past the ',' delimiter and cause a heap buffer overflow. The fix checks if the charset specification is empty after strip() and returns EINVAL immediately, preventing the overflow and following the approach described in BZ #34574. CVE-2026-18374 - CVSS 4.9 (AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) Reported-by: AISLE in partnership with Red Hat Signed-off-by: Dongkyun Son <dongkyun.s@samsung.com> Reviewed-by: Florian Weimer <fweimer@redhat.com>
This commit is contained in:
committed by
Florian Weimer
parent
058c1c63e9
commit
9765a538eb
+7
-5
@@ -355,12 +355,14 @@ _IO_new_file_fopen (FILE *fp, const char *filename, const char *mode,
|
|||||||
*((char *) __mempcpy (ccs, cs + 5, endp - (cs + 5))) = '\0';
|
*((char *) __mempcpy (ccs, cs + 5, endp - (cs + 5))) = '\0';
|
||||||
strip (ccs, ccs);
|
strip (ccs, ccs);
|
||||||
|
|
||||||
if (__wcsmbs_named_conv (&fcts, ccs[2] == '\0'
|
/* After stripping, ccs[2] == '\0' means the charset name is empty.
|
||||||
? upstr (ccs, cs + 5) : ccs) != 0)
|
This is not a valid charset and would cause problems downstream.
|
||||||
|
Reject it with EINVAL (BZ #34574, CVE-2026-18374). */
|
||||||
|
if (ccs[2] == '\0' || __wcsmbs_named_conv (&fcts, ccs) != 0)
|
||||||
{
|
{
|
||||||
/* Something went wrong, we cannot load the conversion modules.
|
/* Either the charset name is empty after strip(), or conversion
|
||||||
This means we cannot proceed since the user explicitly asked
|
modules cannot be loaded. This means we cannot proceed since
|
||||||
for these. */
|
the user explicitly asked for character conversion. */
|
||||||
(void) _IO_file_close_it (fp);
|
(void) _IO_file_close_it (fp);
|
||||||
free (ccs);
|
free (ccs);
|
||||||
__set_errno (EINVAL);
|
__set_errno (EINVAL);
|
||||||
|
|||||||
Reference in New Issue
Block a user