| From 52a9dab6d892763b2a8334a568bd4e2c1a6fde66 Mon Sep 17 00:00:00 2001 |
| From: Kees Cook <keescook@chromium.org> |
| Date: Sun, 13 Feb 2022 10:24:43 -0800 |
| Subject: libsubcmd: Fix use-after-free for realloc(..., 0) |
| MIME-Version: 1.0 |
| Content-Type: text/plain; charset=UTF-8 |
| Content-Transfer-Encoding: 8bit |
| |
| From: Kees Cook <keescook@chromium.org> |
| |
| commit 52a9dab6d892763b2a8334a568bd4e2c1a6fde66 upstream. |
| |
| GCC 12 correctly reports a potential use-after-free condition in the |
| xrealloc helper. Fix the warning by avoiding an implicit "free(ptr)" |
| when size == 0: |
| |
| In file included from help.c:12: |
| In function 'xrealloc', |
| inlined from 'add_cmdname' at help.c:24:2: subcmd-util.h:56:23: error: pointer may be used after 'realloc' [-Werror=use-after-free] |
| 56 | ret = realloc(ptr, size); |
| | ^~~~~~~~~~~~~~~~~~ |
| subcmd-util.h:52:21: note: call to 'realloc' here |
| 52 | void *ret = realloc(ptr, size); |
| | ^~~~~~~~~~~~~~~~~~ |
| subcmd-util.h:58:31: error: pointer may be used after 'realloc' [-Werror=use-after-free] |
| 58 | ret = realloc(ptr, 1); |
| | ^~~~~~~~~~~~~~~ |
| subcmd-util.h:52:21: note: call to 'realloc' here |
| 52 | void *ret = realloc(ptr, size); |
| | ^~~~~~~~~~~~~~~~~~ |
| |
| Fixes: 2f4ce5ec1d447beb ("perf tools: Finalize subcmd independence") |
| Reported-by: Valdis Klētnieks <valdis.kletnieks@vt.edu> |
| Signed-off-by: Kees Kook <keescook@chromium.org> |
| Tested-by: Valdis Klētnieks <valdis.kletnieks@vt.edu> |
| Tested-by: Justin M. Forbes <jforbes@fedoraproject.org> |
| Acked-by: Josh Poimboeuf <jpoimboe@redhat.com> |
| Cc: linux-hardening@vger.kernel.org |
| Cc: Valdis Klētnieks <valdis.kletnieks@vt.edu> |
| Link: http://lore.kernel.org/lkml/20220213182443.4037039-1-keescook@chromium.org |
| Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| tools/lib/subcmd/subcmd-util.h | 11 ++--------- |
| 1 file changed, 2 insertions(+), 9 deletions(-) |
| |
| --- a/tools/lib/subcmd/subcmd-util.h |
| +++ b/tools/lib/subcmd/subcmd-util.h |
| @@ -50,15 +50,8 @@ static NORETURN inline void die(const ch |
| static inline void *xrealloc(void *ptr, size_t size) |
| { |
| void *ret = realloc(ptr, size); |
| - if (!ret && !size) |
| - ret = realloc(ptr, 1); |
| - if (!ret) { |
| - ret = realloc(ptr, size); |
| - if (!ret && !size) |
| - ret = realloc(ptr, 1); |
| - if (!ret) |
| - die("Out of memory, realloc failed"); |
| - } |
| + if (!ret) |
| + die("Out of memory, realloc failed"); |
| return ret; |
| } |
| |