string: strerror, strsignal cannot use buffer after dlmopen (bug 32026)

Secondary namespaces have a different malloc.  Allocating the
buffer in one namespace and freeing it another results in
heap corruption.  Fix this by using a static string (potentially
translated) in secondary namespaces.  It would also be possible
to use the malloc from the initial namespace to manage the
buffer, but these functions would still not be safe to use in
auditors etc. because a call to strerror could still free a
buffer while it is used by the application.  Another approach
could use proper initial-exec TLS, duplicated in secondary
namespaces, but that would need a callback interface for freeing
libc resources in namespaces on thread exit, which does not exist
today.

Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
This commit is contained in:
Florian Weimer 2024-08-19 15:48:03 +02:00
parent e7c14e542d
commit 25a5eb4010
2 changed files with 45 additions and 24 deletions

View File

@ -20,7 +20,7 @@
#include <stdio.h> #include <stdio.h>
#include <string.h> #include <string.h>
#include <tls-internal.h> #include <tls-internal.h>
#include <libc-internal.h>
static const char * static const char *
translate (const char *str, locale_t loc) translate (const char *str, locale_t loc)
@ -31,6 +31,12 @@ translate (const char *str, locale_t loc)
return res; return res;
} }
static char *
unknown_error (locale_t loc)
{
return (char *) translate ("Unknown error", loc);
}
/* Return a string describing the errno code in ERRNUM. */ /* Return a string describing the errno code in ERRNUM. */
char * char *
@ -39,6 +45,8 @@ __strerror_l (int errnum, locale_t loc)
int saved_errno = errno; int saved_errno = errno;
char *err = (char *) __get_errlist (errnum); char *err = (char *) __get_errlist (errnum);
if (__glibc_unlikely (err == NULL)) if (__glibc_unlikely (err == NULL))
{
if (__libc_initial)
{ {
struct tls_internal_t *tls_internal = __glibc_tls_internal (); struct tls_internal_t *tls_internal = __glibc_tls_internal ();
free (tls_internal->strerror_l_buf); free (tls_internal->strerror_l_buf);
@ -50,9 +58,14 @@ __strerror_l (int errnum, locale_t loc)
/* The memory was freed above. */ /* The memory was freed above. */
tls_internal->strerror_l_buf = NULL; tls_internal->strerror_l_buf = NULL;
/* Provide a fallback translation. */ /* Provide a fallback translation. */
err = (char *) translate ("Unknown error", loc); err = unknown_error (loc);
} }
} }
else
/* Secondary namespaces use a different malloc, so cannot
participate in the buffer management. */
err = unknown_error (loc);
}
else else
err = (char *) translate (err, loc); err = (char *) translate (err, loc);

View File

@ -21,6 +21,7 @@
#include <string.h> #include <string.h>
#include <libintl.h> #include <libintl.h>
#include <tls-internal.h> #include <tls-internal.h>
#include <libc-internal.h>
/* Return a string describing the meaning of the signal number SIGNUM. */ /* Return a string describing the meaning of the signal number SIGNUM. */
char * char *
@ -30,6 +31,8 @@ strsignal (int signum)
if (desc != NULL) if (desc != NULL)
return _(desc); return _(desc);
if (__libc_initial)
{
struct tls_internal_t *tls_internal = __glibc_tls_internal (); struct tls_internal_t *tls_internal = __glibc_tls_internal ();
free (tls_internal->strsignal_buf); free (tls_internal->strsignal_buf);
@ -43,8 +46,13 @@ strsignal (int signum)
r = __asprintf (&tls_internal->strsignal_buf, _("Unknown signal %d"), r = __asprintf (&tls_internal->strsignal_buf, _("Unknown signal %d"),
signum); signum);
if (r == -1) if (r >= 0)
tls_internal->strsignal_buf = NULL;
return tls_internal->strsignal_buf; return tls_internal->strsignal_buf;
else
tls_internal->strsignal_buf = NULL;
}
/* Fall through on asprintf error, and for !__libc_initial:
secondary namespaces use a different malloc and cannot
participate in the buffer management. */
return _("Unknown signal");
} }