From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [216.205.24.124]) by sourceware.org (Postfix) with ESMTP id 3544F3835830 for ; Thu, 19 Aug 2021 15:38:55 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org 3544F3835830 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1629387534; h=from:from:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type:in-reply-to:in-reply-to: references:references; bh=bHhgXg4HSOVj18sRHUEwMP3xzEmhYmR7+/3LVeZXTkw=; b=AybnrCKI4GSDbKvze0/20HmiTjzmfzgqBbOlU5Fs5anYkLW+PqYZO2dOeC33Bd+0dsm73m mcJQONfUResut1Gxa0pN7hmcaXRlB4WxDbpuSt2tSvpxjehTKXf7SyGZVymnNg21N902HE sqtDRIhOKn1PvWrFFfr2WwbVesqZv+o= Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-593-gUCFUOGkP6iQD3Um3VwVqg-1; Thu, 19 Aug 2021 11:38:53 -0400 X-MC-Unique: gUCFUOGkP6iQD3Um3VwVqg-1 Received: from smtp.corp.redhat.com (int-mx08.intmail.prod.int.phx2.redhat.com [10.5.11.23]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id C3035875112 for ; Thu, 19 Aug 2021 15:38:52 +0000 (UTC) Received: from calimero.vinschen.de (ovpn-112-10.ams2.redhat.com [10.36.112.10]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 95C4F1970F for ; Thu, 19 Aug 2021 15:38:52 +0000 (UTC) Received: by calimero.vinschen.de (Postfix, from userid 500) id 35488A80BC1; Thu, 19 Aug 2021 17:38:51 +0200 (CEST) Date: Thu, 19 Aug 2021 17:38:51 +0200 From: Corinna Vinschen To: newlib@sourceware.org Subject: Re: [PATCH] svfwscanf: Simplify _sungetwc_r to eliminate apparent buffer overflow Message-ID: Reply-To: newlib@sourceware.org Mail-Followup-To: newlib@sourceware.org References: <874kbnevjm.fsf@keithp.com> <87bl5ud8bq.fsf@keithp.com> <878s0yd7em.fsf@keithp.com> <87wnohbh14.fsf@keithp.com> MIME-Version: 1.0 In-Reply-To: <87wnohbh14.fsf@keithp.com> X-Scanned-By: MIMEDefang 2.84 on 10.5.11.23 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=vinschen@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=utf-8 Content-Disposition: inline X-Spam-Status: No, score=-7.2 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H2, SPF_HELO_NONE, SPF_NONE, TXREP autolearn=ham autolearn_force=no version=3.4.4 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on server2.sourceware.org X-BeenThere: newlib@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Newlib mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Aug 2021 15:38:56 -0000 [Please don't CC me, I'm reading the ML all the time. Thanks] On Aug 19 08:17, Keith Packard wrote: > Corinna Vinschen writes: > > > Given all chars are sizeof(wchar_t), how's the buffer ever going to > > become unaligned? > > It places the wchar_t at the end of _ubuf, which is 3 bytes long, making > it unaligned: > > fp->_p = &fp->_ubuf[sizeof (fp->_ubuf) - sizeof (wchar_t)]; Oops, right. Thanks, Corinna