git: dec68aeff8ce - main - libc/stdlib/getenv.c: always allocate new environment
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 02 Oct 2026 20:01:48 UTC
The branch main has been updated by kib:
URL: https://cgit.FreeBSD.org/src/commit/?id=dec68aeff8ce0ce154e93325a74bba6af71c87af
commit dec68aeff8ce0ce154e93325a74bba6af71c87af
Author: Konstantin Belousov <kib@FreeBSD.org>
AuthorDate: 2026-09-24 18:30:57 +0000
Commit: Konstantin Belousov <kib@FreeBSD.org>
CommitDate: 2026-10-02 19:48:42 +0000
libc/stdlib/getenv.c: always allocate new environment
in particular, if the old environment is NULL.
Among making it less surprising for userspace to observe NULL environ,
the change also prevents NULL deref in __rebuild_environ() when
terminating the empty as NULL environment with the NULL pointer.
Reported by: Leo Bicknell <bicknell@ufp.org>
PR: 298747
Reviewed by: emaste, markj
Sponsored by: The FreeBSD Foundation
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D59996
---
lib/libc/stdlib/getenv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/libc/stdlib/getenv.c b/lib/libc/stdlib/getenv.c
index c1d0b7a559d5..1fff081002e2 100644
--- a/lib/libc/stdlib/getenv.c
+++ b/lib/libc/stdlib/getenv.c
@@ -268,7 +268,7 @@ __rebuild_environ(int newEnvironSize)
int tmpEnvironSize;
/* Resize environ. */
- if (newEnvironSize > environSize) {
+ if (newEnvironSize > environSize || intEnviron == NULL) {
tmpEnvironSize = newEnvironSize * 2;
tmpEnviron = reallocarray(intEnviron, tmpEnvironSize + 1,
sizeof(*intEnviron));