| Message ID | 20251029141606.59951-2-ant.v.moryakov@gmail.com (mailing list archive) |
|---|---|
| State | Changes Requested |
| Headers |
Return-Path: <libc-alpha-bounces~patchwork=sourceware.org@sourceware.org> X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id B7296385625D for <patchwork@sourceware.org>; Wed, 29 Oct 2025 14:18:05 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B7296385625D Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20230601 header.b=XI6Rx9Bu X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-lf1-x12b.google.com (mail-lf1-x12b.google.com [IPv6:2a00:1450:4864:20::12b]) by sourceware.org (Postfix) with ESMTPS id E2AE23858427 for <libc-alpha@sourceware.org>; Wed, 29 Oct 2025 14:16:17 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org E2AE23858427 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org E2AE23858427 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=2a00:1450:4864:20::12b ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1761747378; cv=none; b=Na0mM0Ld2D+16Ibf0oIh21ESrO6GJ0X/hf8r65iSto/ieUG6KrXMRdExmOf/7k4l5bYLhtaolBuSkLnSVZW8zayMQOXPiYyzJ9D+FDYLE1NoiKo+toTU7+w5CdGeq0PDn5m+C6ISzCs+xWG+cex+LCblFxV+3RGpklWfgg0kHaY= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1761747378; c=relaxed/simple; bh=DmuQAtISWhtOlVJiLY2VyILc6xK/xWmOLBwLU67xkf0=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=DV57ROSYvfw0tI7pxTnP1NTg+Rws1lpDE3ZYw4qqxp+ZGuqex2rTRs7fSXQDZ/1lee8um7wXf81QCW0QXyrvtXQ7QTlXfpYAnLME+cY2rOZ4aJak3LAlOLfNcUjx02WQbvcLliQl175ioiPBY4H4qPH2B5PIwyEokvwerdYj2tc= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E2AE23858427 Received: by mail-lf1-x12b.google.com with SMTP id 2adb3069b0e04-592fd97c03eso6982263e87.1 for <libc-alpha@sourceware.org>; Wed, 29 Oct 2025 07:16:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1761747376; x=1762352176; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=M8M6/xgIP8ozLILoCVBHQA4Ihj0HMb9csK6gLlomD7E=; b=XI6Rx9BuHsWKtkukG9O/v7kvBmxAi6oDTz9DSEGmw7iiRolifuKaPVBzCkpua8I9tK q+CZ+PEEvQoiuKMFUkfRhMIPNnmYDUU3eC1P3ZD/hs/+REPHmm+BKokOfXG2a3h3g3Ol 5z5m2HGsr0rM9959KBCIKwcRfS3fLcKRFMe3QOzHEn6A5tA8pJ85fjS2MEPEN+/82Pzs mKn+jlRAZZhq3hykQ9GwbXyfuIRGQJX569evS1i71rNaBRwfnuQpy2CCSPrH6k9pYA2f Ea+PXof5rBa7EfjT82liZZqeLvrLrW80wFnpaue0+VWN4jvpnoVlRhBWrJeZgTcAE4pT 7QsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1761747376; x=1762352176; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=M8M6/xgIP8ozLILoCVBHQA4Ihj0HMb9csK6gLlomD7E=; b=DqUUtsXabPlsTxh4LYeWBxs9X1/lS6iU/2jH3KIX9sDmIq8HwuEqzMAJv1ZeSInB7/ lMUHztMcdwlwmMsOJybdWWSf/04noab/kKzplOkGPpTQdQGtVWyzZC6x3neN0Cm/FrSL Zx7QK812SNq2aSzKdqgS9VoFQELzcpStmtKOEoashH9qbUPAwJRIx/+O2NWbMpaCpj8N 3SkZtdzgFyRw3W+jYy9dfEoVfPcETUcshnGuRmSx5Oy1fAt6Kya6H7IobC6mNDqKOC7L 4mO2chX3KtadtzmVHO6OFtruKKXNrnv2noS/nltgTm9qZX/+AFtkcITE1mNn6Pch9P5G lUTw== X-Gm-Message-State: AOJu0YxTPEerLLJ3Wg+o7MCnPJMvSztm+xMQTljffBrDem35BePpxDf4 oNnJVYAyUSZ0fWTt6jP5zCa0ijtavsXirnncW4Q/vULHEX6dqAdFIb10kH2V1JNk4mQ= X-Gm-Gg: ASbGncu5caiB98695R8mvZ5vbKDt2O19TUwb0M0D8S1T5Vo0OX1c2cTdMLrulkaRE4N 22WJSMH7zUktFLa/kIioXnueDjycYvRpku7kR7EOt1g9MYeR+vAgSON7LFRucsmCWWIcKNXeaiu QpQrmBfMOyYaxUAtL2q4IMmd3IIVYIfxJn77N5bK61vQRVb0X/xJVnFdaZJ4IBHUDBIh6qSVtLa celdMEQdiEG/rNFqj9S8GkL07GjZRpLM83wQyTP8qHKLxSk0qMmP/Q7U7YjD3t/wfQ0LzXy2Fp8 EQxMdt3mDud6WcyLUGnsiguwzGIkc4fGtCaPhEB4oCXhtX/tdTGycVKaMhOL6lE374pG3TX8Gso 9Iu5gYtn3J8Xq+0XGFgHeYADX0CK7U2L9PhgG+tDcHjTFyqxaFR/7NzoeJGn5yqRju2rw4+K7Lv xgnkww74NnQ3dDZCX3MBQDiOHa+ZcbqHApdTLy+dRgJ+TTbXa1sA== X-Google-Smtp-Source: AGHT+IH88cwXZcFtaBubkRV22VCK9IZ3OH+B4Xhyx9A3syCVplnywieQDqkXkp4FwkNKTaBKb5QJQA== X-Received: by 2002:a05:6512:104e:b0:592:f73f:1226 with SMTP id 2adb3069b0e04-5941287d8c8mr1071332e87.22.1761747375735; Wed, 29 Oct 2025 07:16:15 -0700 (PDT) Received: from lnb0tqzjk.rasu.local (109-252-120-31.nat.spd-mgts.ru. [109.252.120.31]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-59301f6974esm3965040e87.73.2025.10.29.07.16.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 29 Oct 2025 07:16:14 -0700 (PDT) From: Anton Moryakov <ant.v.moryakov@gmail.com> To: libc-alpha@sourceware.org Cc: Anton Moryakov <ant.v.moryakov@gmail.com> Subject: [PATCH] iconv: skeleton.c: Fix potential NULL dereference in FUNCTION_NAME Date: Wed, 29 Oct 2025 17:16:04 +0300 Message-Id: <20251029141606.59951-2-ant.v.moryakov@gmail.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20251029141606.59951-1-ant.v.moryakov@gmail.com> References: <20251029141606.59951-1-ant.v.moryakov@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-12.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list <libc-alpha.sourceware.org> List-Unsubscribe: <https://sourceware.org/mailman/options/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=unsubscribe> List-Archive: <https://sourceware.org/pipermail/libc-alpha/> List-Post: <mailto:libc-alpha@sourceware.org> List-Help: <mailto:libc-alpha-request@sourceware.org?subject=help> List-Subscribe: <https://sourceware.org/mailman/listinfo/libc-alpha>, <mailto:libc-alpha-request@sourceware.org?subject=subscribe> Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org |
| Series |
iconv: skeleton.c: Fix potential NULL dereference in FUNCTION_NAME
|
|
Checks
| Context | Check | Description |
|---|---|---|
| redhat-pt-bot/TryBot-apply_patch | success | Patch applied to master at the time it was sent |
| redhat-pt-bot/TryBot-32bit | success | Build for i686 |
Commit Message
Anton Moryakov
Oct. 29, 2025, 2:16 p.m. UTC
Report of the static analyzer:
After being compared to a NULL value at skeleton.c:516, pointer
'irreversible' is dereferenced at skeleton.c:662. This indicates a
potential null pointer dereference vulnerability.
Correct explained:
The pointer 'irreversible' is checked for NULL when initializing
'lirreversiblep' (used in conversion loops), but later unconditionally
dereferenced in the exit path when updating the irreversible counter.
This creates an inconsistency: if the function is called with
irreversible == NULL, and the conversion loop completes successfully,
the final update '*irreversible += lirreversible' will cause a
segmentation fault.
Add a NULL check before dereferencing to prevent the crash. This ensures
consistent behavior with the earlier initialization logic and eliminates
the risk of undefined behavior.
Signed-off-by: Anton Moryakov <ant.v.moryakov@gmail.com>
---
iconv/skeleton.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
Comments
On 29/10/25 11:16, Anton Moryakov wrote: > Report of the static analyzer: > After being compared to a NULL value at skeleton.c:516, pointer > 'irreversible' is dereferenced at skeleton.c:662. This indicates a > potential null pointer dereference vulnerability. > > Correct explained: > The pointer 'irreversible' is checked for NULL when initializing > 'lirreversiblep' (used in conversion loops), but later unconditionally > dereferenced in the exit path when updating the irreversible counter. > This creates an inconsistency: if the function is called with > irreversible == NULL, and the conversion loop completes successfully, > the final update '*irreversible += lirreversible' will cause a > segmentation fault. > > Add a NULL check before dereferencing to prevent the crash. This ensures > consistent behavior with the earlier initialization logic and eliminates > the risk of undefined behavior. > > Signed-off-by: Anton Moryakov <ant.v.moryakov@gmail.com> Do we have a testcase that triggers this issue? And do we need a bug report for this? > --- > iconv/skeleton.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/iconv/skeleton.c b/iconv/skeleton.c > index 7523694b81..4565beff33 100644 > --- a/iconv/skeleton.c > +++ b/iconv/skeleton.c > @@ -533,7 +533,8 @@ FUNCTION_NAME (struct __gconv_step *step, struct __gconv_step_data *data, > > /* Remember how many non-identical characters we > converted in an irreversible way. */ > - *irreversible += lirreversible; > + if (irreversible != NULL) > + *irreversible += lirreversible; > > break; > }
diff --git a/iconv/skeleton.c b/iconv/skeleton.c index 7523694b81..4565beff33 100644 --- a/iconv/skeleton.c +++ b/iconv/skeleton.c @@ -533,7 +533,8 @@ FUNCTION_NAME (struct __gconv_step *step, struct __gconv_step_data *data, /* Remember how many non-identical characters we converted in an irreversible way. */ - *irreversible += lirreversible; + if (irreversible != NULL) + *irreversible += lirreversible; break; }