From nobody Tue Oct 25 21:51:25 2022 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Mxly60Gslz4g5xS; Tue, 25 Oct 2022 21:51:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Mxly56B35z3g8Q; Tue, 25 Oct 2022 21:51:25 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1666734685; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=eU/f+0sS7RolCIUochv/9lnEImMhpOuGexDqssvV5Fo=; b=hq9w6C0uvNDM6YxY+BJKMUiczkwFr/n9/ad/951zTTg/8UUGfJVcaj4+a1NWWbg/atfmXJ hEYKOnZNn5XRqkgUwyaUQf9sGdHzHctY3eqObHKvonyi2JvkhzZ/zbFHd0wI6rFdU645i+ hINO+17WKPJFOBo2I+nlSO3mt/XdFAZQDAJrcnxuBTHOEBGzbBdx0nDxWc+Pu3CmxPHkQB 0HSI9n91DMkF3kYr8G4YZONMGb7g8XJt8wdcII2pQWf30nnXcpLX3N6veLYmgYM/Gj/lIK 6j9CzO5sc0eL6OvCg9ws8uFLVTnEXNncacSRJ4awA0tc7WXXqx8Hyi3UTDjIpg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Mxly54zQFztNv; Tue, 25 Oct 2022 21:51:25 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 29PLpP1m085949; Tue, 25 Oct 2022 21:51:25 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 29PLpPDJ085948; Tue, 25 Oct 2022 21:51:25 GMT (envelope-from git) Date: Tue, 25 Oct 2022 21:51:25 GMT Message-Id: <202210252151.29PLpPDJ085948@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Konstantin Belousov Subject: git: 9e03b903e377 - main - strfmon: Avoid an out-of-bounds access List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 9e03b903e377c75a60cbbb89ed78955769a1c804 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1666734685; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=eU/f+0sS7RolCIUochv/9lnEImMhpOuGexDqssvV5Fo=; b=j8TK0qEM1aaQfOLi0ugLHJBvCSH5cReBJ3ErnXEsP+WIuOVQ77TDWUQINXJLtZ0oswJdca yHtsgwYnKBRnGjYi20jbyw0KU3Pv070VfL/LUYXtadQwCm3bhuFMHkKoXSSqLr7jR2i0q/ iSqAwUxE7cWz6kZw4QoJPaieYS2bI3eygH6bypWPFSlb1CUYLMCa66S19Rrf8QNsEwkU++ MvLnMT3YLECIRXb02i3QMqKajG/7EBQ7+EG1orF9gN6CyuiOHQtumxxefaFC3/NK1xeUnD 5ZbqRqx09GIhmEfF9c8hysOy2vIlumzXVAFai0eXYUvnPH7g3wJquBlZfwB2vw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1666734685; a=rsa-sha256; cv=none; b=WO2QbzdupR88jrfw0h/vA1+FYGpr3Cai1NI4IAbxKddDaurkPTlwzlH34MKwUIT3qK87+C w0QM5fQqkt2V4Fsp6K5Zy/b4BMQkjnIZvEQ6Z7s7rT2Z0jwx1OKpB0Muz+ZsYFia/rP4Xq tvSawMTJbykjcrriIIfVseqC5vnbZgs1MQ6L/3gBw2D1e15qec015ZmqKHHoSdSlIkC2Vw +A1uRu1+Dop1/aNkq2Iy3IibQ22xE9Gc63/x/RypsvBh86vjrXcnNvzYxFk+GI8Ll2dLnk T6x40f0lb0LdUsRHD/8+cSNy3b35x2aVXVc7znuEBNn+tr3Ef7YDgeOhENWKxw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/src/commit/?id=9e03b903e377c75a60cbbb89ed78955769a1c804 commit 9e03b903e377c75a60cbbb89ed78955769a1c804 Author: Jose Luis Duran AuthorDate: 2022-10-13 15:51:27 +0000 Commit: Konstantin Belousov CommitDate: 2022-10-25 21:40:17 +0000 strfmon: Avoid an out-of-bounds access Avoid an out-of-bounds access when trying to set the space_char using an international currency format (%i) and the C/POSIX locale. The current code tries to read the SPACE from int_curr_symbol[3]: currency_symbol = strdup(lc->int_curr_symbol); space_char = *(currency_symbol+3); But on C/POSIX locales, int_curr_symbol is empty. Three implementations have been examined: NetBSD[1], Darwin[2], and Illumos[3]. Only NetBSD has fixed it[4]. Darwin and NetBSD also trim the mandatory final SPACE character after reading it. Locale Format Darwin/NetBSD FreeBSD/Illumos en_US.UTF-8 [%i] [USD123.45] [USD 123.45] fr_FR.UTF-8 [%i] [123,45 EUR] [123,45 EUR ] This commit only fixes the out-of-bounds access. [1]: https://github.com/NetBSD/src/blob/trunk/lib/libc/stdlib/strfmon.c [2]: https://opensource.apple.com/source/Libc/Libc-1439.141.1/stdlib/NetBSD/strfmon.c.auto.html [3]: https://github.com/illumos/illumos-gate/blob/master/usr/src/lib/libc/port/locale/strfmon.c [4]: https://github.com/NetBSD/src/commit/3d7b5d498aa9609f2bc9ece9c734c5f493a8e239 Reviewed by: kib PR: 267282 Github PR: #619 MFC after: 1 week --- lib/libc/stdlib/strfmon.c | 5 +++-- lib/libc/tests/stdlib/strfmon_test.c | 2 +- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/lib/libc/stdlib/strfmon.c b/lib/libc/stdlib/strfmon.c index fbb1f79a87d5..2526ab8fd8b1 100644 --- a/lib/libc/stdlib/strfmon.c +++ b/lib/libc/stdlib/strfmon.c @@ -239,8 +239,9 @@ vstrfmon_l(char * __restrict s, size_t maxsize, locale_t loc, free(currency_symbol); if (flags & USE_INTL_CURRENCY) { currency_symbol = strdup(lc->int_curr_symbol); - if (currency_symbol != NULL) - space_char = *(currency_symbol+3); + if (currency_symbol != NULL && + strlen(currency_symbol) > 3) + space_char = currency_symbol[3]; } else currency_symbol = strdup(lc->currency_symbol); diff --git a/lib/libc/tests/stdlib/strfmon_test.c b/lib/libc/tests/stdlib/strfmon_test.c index 3e77a4f5290f..dc328e974bb8 100644 --- a/lib/libc/tests/stdlib/strfmon_test.c +++ b/lib/libc/tests/stdlib/strfmon_test.c @@ -197,7 +197,7 @@ ATF_TC_BODY(strfmon_international_currency_code, tc) } tests[] = { { "en_US.UTF-8", "[USD 123.45]" }, /* XXX */ { "de_DE.UTF-8", "[123,45 EUR ]" }, /* XXX */ - { "C", "[123.45]" }, /* XXX OOB access */ + { "C", "[123.45]" }, }; size_t i; char actual[100];