diff options
| author | Ed Maste <emaste@FreeBSD.org> | 2022-10-03 18:24:42 +0000 |
|---|---|---|
| committer | Ed Maste <emaste@FreeBSD.org> | 2022-10-04 16:03:56 +0000 |
| commit | 9515313b26beb005a521aff2e6edd4d75cd010da (patch) | |
| tree | c09e4dfa1e31bc09602f1ac9f845b35e60a8e7f3 | |
| parent | 89e5ef8917af900558c2d275f5d5c4c703520ead (diff) | |
libc: Fix size range check in setvbuf
From enh at google.com via openbsd-tech mailing list via pfg@:
The existing test is wrong for LP64, where size_t has twice as many
relevant bits as int, not just one. (Found by inspection by
rprichard.)
| -rw-r--r-- | lib/libc/stdio/setvbuf.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/lib/libc/stdio/setvbuf.c b/lib/libc/stdio/setvbuf.c index 03a3c7263125..8947e61e7c29 100644 --- a/lib/libc/stdio/setvbuf.c +++ b/lib/libc/stdio/setvbuf.c @@ -39,6 +39,7 @@ static char sccsid[] = "@(#)setvbuf.c 8.2 (Berkeley) 11/16/93"; __FBSDID("$FreeBSD$"); #include "namespace.h" +#include <limits.h> #include <stdio.h> #include <stdlib.h> #include "un-namespace.h" @@ -62,7 +63,7 @@ setvbuf(FILE * __restrict fp, char * __restrict buf, int mode, size_t size) * when setting _IONBF. */ if (mode != _IONBF) - if ((mode != _IOFBF && mode != _IOLBF) || (int)size < 0) + if ((mode != _IOFBF && mode != _IOLBF) || size > INT_MAX) return (EOF); FLOCKFILE_CANCELSAFE(fp); |
