1
0
mirror of git://git.sv.gnu.org/coreutils.git synced 2026-08-07 09:11:11 +02:00

numfmt: fix buffer over-read (CWE-126)

* src/numfmt.c (simple_strtod_human): Check for NULL after pointer
adjustment to avoid Out-of-range pointer offset (CWE-823).
* NEWS: Mention the fix.
This commit is contained in:
Pádraig Brady
2025-10-11 12:19:34 +01:00
parent dd3eab13ee
commit b880b02c44
3 changed files with 12 additions and 3 deletions
+3
View File
@@ -18,6 +18,9 @@ GNU coreutils NEWS -*- outline -*-
Also non standard SHA2 tags with a bad length resulted in undefined behavior.
[bug introduced in coreutils-9.8]
'numfmt' no longer reads out-of-bounds memory with trailing blanks in input.
[bug introduced with numfmt in coreutils-8.21]
'rm -d DIR' no longer fails on Ceph snapshot directories.
Although these directories are nonempty, 'rmdir DIR' succeeds on them.
[bug introduced in coreutils-8.16]
+8 -3
View File
@@ -641,7 +641,7 @@ simple_strtod_human (char const *input_str,
devmsg (" parsed numeric value: %Lf\n"
" input precision = %d\n", *value, (int)*precision);
if (**endptr != '\0')
while (**endptr)
{
/* process suffix. */
@@ -649,6 +649,9 @@ simple_strtod_human (char const *input_str,
while (isblank (to_uchar (**endptr)))
(*endptr)++;
if (**endptr == '\0')
break; /* Treat as no suffix. */
if (!valid_suffix (**endptr))
return SSE_INVALID_SUFFIX;
@@ -661,9 +664,9 @@ simple_strtod_human (char const *input_str,
if (allowed_scaling == scale_auto && **endptr == 'i')
{
/* auto-scaling enabled, and the first suffix character
is followed by an 'i' (e.g. Ki, Mi, Gi). */
is followed by an 'i' (e.g. Ki, Mi, Gi). */
scale_base = 1024;
(*endptr)++; /* skip second ('i') suffix character. */
(*endptr)++; /* skip 'i' in suffix. */
devmsg (" Auto-scaling, found 'i', switching to base %d\n",
scale_base);
}
@@ -676,6 +679,8 @@ simple_strtod_human (char const *input_str,
}
*precision = 0; /* Reset, to select precision based on scale. */
break;
}
long double multiplier = powerld (scale_base, power);
+1
View File
@@ -163,6 +163,7 @@ my @Tests =
['suf-20',
'--suffix=Foo' . 'x' x 122 . 'y 0',
{OUT => '0Foo' . 'x' x 122 . 'y'}],
['suf-21', "-d '' --from=si '4 '", {OUT => "4"}],
## GROUPING