glibc/debug
Florian Weimer 7b52c8ae05 libio: Avoid _allocate_buffer, _free_buffer function pointers [BZ #23236]
These unmangled function pointers reside on the heap and could
be targeted by exploit writers, effectively bypassing libio vtable
validation.  Instead, we ignore these pointers and always call
malloc or free.

In theory, this is a backwards-incompatible change, but using the
global heap instead of the user-supplied callback functions should
have little application impact.  (The old libstdc++ implementation
exposed this functionality via a public, undocumented constructor
in its strstreambuf class.)

(cherry picked from commit 4e8a6346cd)
2018-06-01 11:24:58 +02:00
..
asprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
backtrace-tst.c Add #include <stdint.h> for uint[32|64]_t usage (except installed headers). 2013-05-16 11:32:54 -05:00
backtrace.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
backtracesyms.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
backtracesymsfd.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
catchsegv.sh Update copyright dates not handled by scripts/update-copyrights. 2017-01-01 00:26:24 +00:00
chk_fail.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
confstr_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
Depend
dprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
execinfo.h Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
explicit_bzero_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fdelt_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fgets_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fgets_u_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fgetws_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fgetws_u_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fortify_fail.c Avoid accessing corrupted stack from __stack_chk_fail [BZ #21752] 2017-07-24 06:06:24 -07:00
fprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fread_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fread_u_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
fwprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
getcwd_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
getdomainname_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
getgroups_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
gethostname_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
gets_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
getwd_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
longjmp_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
Makefile Don't add stack_chk_fail_local.o to libc.a [BZ #21740] 2017-07-19 08:21:46 -07:00
mbsnrtowcs_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
mbsrtowcs_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
mbstowcs_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
memcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
memmove_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
mempcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
memset_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
noophooks.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
obprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
pcprofile.c Narrowing the visibility of libc-internal.h even further. 2017-03-01 20:33:46 -05:00
pcprofiledump.c Update copyright dates not handled by scripts/update-copyrights. 2017-01-01 00:26:24 +00:00
poll_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
ppoll_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
pread64_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
pread_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
printf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
read_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
readlink_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
readlinkat_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
readonly-area.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
realpath_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
recv_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
recvfrom_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
segfault.c Fix struct sigaltstack namespace (bug 21517). 2017-06-05 10:17:46 +00:00
snprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
sprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
stack_chk_fail_local.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
stack_chk_fail.c Avoid backtrace from __stack_chk_fail [BZ #12189] 2017-07-11 07:44:14 -07:00
stpcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
stpncpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
strcat_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
strcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
strncat_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
strncpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
swprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
test-stpcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
test-strcpy_chk.c Update string tests to use the support test driver. 2017-03-23 11:32:29 -03:00
tst-backtrace2.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-backtrace3.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-backtrace4.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-backtrace5.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-backtrace6.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-backtrace.h Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-chk1.c Clean up conditionals for declaration of gets. 2017-02-25 09:47:51 -05:00
tst-chk2.c
tst-chk3.c
tst-chk4.cc
tst-chk5.cc
tst-chk6.cc
tst-lfschk1.c
tst-lfschk2.c
tst-lfschk3.c
tst-lfschk4.cc
tst-lfschk5.cc
tst-lfschk6.cc
tst-longjmp_chk2.c test-skeleton.c: Add write_message function 2016-06-23 11:00:36 +02:00
tst-longjmp_chk3.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
tst-longjmp_chk.c tests: unify fortification handler logic 2014-02-08 06:58:43 -05:00
tst-ssp-1.c Avoid backtrace from __stack_chk_fail [BZ #12189] 2017-07-11 07:44:14 -07:00
ttyname_r_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vasprintf_chk.c libio: Avoid _allocate_buffer, _free_buffer function pointers [BZ #23236] 2018-06-01 11:24:58 +02:00
vdprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
Versions New string function explicit_bzero (from OpenBSD). 2016-12-16 16:21:54 -05:00
vfprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vfwprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vsnprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vsprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vswprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
vwprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
warning-nop.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcpcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcpncpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcrtomb_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcscat_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcscpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcsncat_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcsncpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcsnrtombs_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcsrtombs_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wcstombs_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wctomb_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wmemcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wmemmove_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wmempcpy_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wmemset_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
wprintf_chk.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
xtrace.sh Update copyright dates not handled by scripts/update-copyrights. 2017-01-01 00:26:24 +00:00