public inbox for glibc-bugs@sourceware.org
help / color / mirror / Atom feed
* [Bug libc/27083] New: Unsafe unbounded alloca in addmntent
@ 2020-12-16 14:12 siddhesh at sourceware dot org
  2020-12-16 14:18 ` [Bug libc/27083] " siddhesh at sourceware dot org
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: siddhesh at sourceware dot org @ 2020-12-16 14:12 UTC (permalink / raw)
  To: glibc-bugs

https://sourceware.org/bugzilla/show_bug.cgi?id=27083

            Bug ID: 27083
           Summary: Unsafe unbounded alloca in addmntent
           Product: glibc
           Version: unspecified
            Status: NEW
          Severity: normal
          Priority: P2
         Component: libc
          Assignee: unassigned at sourceware dot org
          Reporter: siddhesh at sourceware dot org
                CC: drepper.fsp at gmail dot com
  Target Milestone: ---

addmntent duplicates strings in its input struct mntent using alloca due to
which very long strings could blow up the stack.

Example:

#include <stdlib.h>
#include <mntent.h>
#include <stdio.h>
#include <string.h>

#define LARGE_VALUE 2*1024*1024*1024ULL

int main(int argc, char **argv) {
  FILE *f = fopen("/dev/null", "w");
  struct mntent bad;

  bad.mnt_fsname = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_fsname, ' ', LARGE_VALUE - 1);
  bad.mnt_dir = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_dir, ' ', LARGE_VALUE - 1);
  bad.mnt_type = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_type, ' ', LARGE_VALUE - 1);
  bad.mnt_opts = calloc (LARGE_VALUE, 1);
  memset (bad.mnt_opts, ' ', LARGE_VALUE - 1);
  bad.mnt_freq = 1;
  bad.mnt_passno = 2;

  addmntent (f, &bad);

  endmntent(f);

  return 0;
}

-- 
You are receiving this mail because:
You are on the CC list for the bug.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2020-12-22 16:05 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-12-16 14:12 [Bug libc/27083] New: Unsafe unbounded alloca in addmntent siddhesh at sourceware dot org
2020-12-16 14:18 ` [Bug libc/27083] " siddhesh at sourceware dot org
2020-12-16 16:32 ` siddhesh at sourceware dot org
2020-12-18 16:04 ` siddhesh at sourceware dot org
2020-12-22 16:05 ` siddhesh at sourceware dot org

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).