From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: by sourceware.org (Postfix, from userid 48) id 67CB1386EC47; Thu, 18 Mar 2021 18:55:42 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 67CB1386EC47 From: "carlos at redhat dot com" To: glibc-bugs@sourceware.org Subject: [Bug dynamic-link/27609] New: In elf/dl-open.c (_dl_open) we might use __LM_ID_CALLER to index GL(dl_ns)[] Date: Thu, 18 Mar 2021 18:55:42 +0000 X-Bugzilla-Reason: CC X-Bugzilla-Type: new X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: glibc X-Bugzilla-Component: dynamic-link X-Bugzilla-Version: 2.33 X-Bugzilla-Keywords: X-Bugzilla-Severity: normal X-Bugzilla-Who: carlos at redhat dot com X-Bugzilla-Status: NEW X-Bugzilla-Resolution: X-Bugzilla-Priority: P2 X-Bugzilla-Assigned-To: unassigned at sourceware dot org X-Bugzilla-Target-Milestone: --- X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_id short_desc product version bug_status bug_severity priority component assigned_to reporter target_milestone Message-ID: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: http://sourceware.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: glibc-bugs@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Glibc-bugs mailing list List-Unsubscribe: , List-Archive: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 18 Mar 2021 18:55:42 -0000 https://sourceware.org/bugzilla/show_bug.cgi?id=3D27609 Bug ID: 27609 Summary: In elf/dl-open.c (_dl_open) we might use __LM_ID_CALLER to index GL(dl_ns)[] Product: glibc Version: 2.33 Status: NEW Severity: normal Priority: P2 Component: dynamic-link Assignee: unassigned at sourceware dot org Reporter: carlos at redhat dot com Target Milestone: --- AFAICT we *might* get here with an __LM_ID_CALLER value... and using -2 into the index would not yield the expected result. 881 /* Avoid keeping around a dangling reference to the libc.so link 882 map in case it has been cached in libc_map. */ 883 if (!args.libc_already_loaded) 884 GL(dl_ns)[nsid].libc_map =3D NULL; 885=20 We should review this and ensure we can never get __LM_ID_CALLER here, or t= hat if we can that it should be OK. It doesn't look we get here because of the guard !args.libc_already_loaded,= but I could be wrong so I'm filling this bug to check on that. --=20 You are receiving this mail because: You are on the CC list for the bug.=