Go to file
H.J. Lu f57666aa30 x86-64 memcmp/wmemcmp: Properly handle the length parameter [BZ #24097]
On x32, the size_t parameter may be passed in the lower 32 bits of a
64-bit register with the non-zero upper 32 bits.  The string/memory
functions written in assembly can only use the lower 32 bits of a
64-bit register as length or must clear the upper 32 bits before using
the full 64-bit register for length.

This pach fixes memcmp/wmemcmp for x32.  Tested on x86-64 and x32.  On
x86-64, libc.so is the same with and withou the fix.

	[BZ #24097]
	CVE-2019-6488
	* sysdeps/x86_64/multiarch/memcmp-avx2-movbe.S: Use RDX_LP for
	length.  Clear the upper 32 bits of RDX register.
	* sysdeps/x86_64/multiarch/memcmp-sse4.S: Likewise.
	* sysdeps/x86_64/multiarch/memcmp-ssse3.S: Likewise.
	* sysdeps/x86_64/x32/Makefile (tests): Add tst-size_t-memcmp and
	tst-size_t-wmemcmp.
	* sysdeps/x86_64/x32/tst-size_t-memcmp.c: New file.
	* sysdeps/x86_64/x32/tst-size_t-wmemcmp.c: Likewise.

(cherry picked from commit b304fc201d)
2019-02-01 12:19:20 -08:00
argp Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
assert Fix uninitialized variable in assert_perror (bug 22761) 2018-02-05 11:06:15 +01:00
benchtests benchtests: improve argument parsing through argparse library 2018-07-19 14:53:37 -05:00
bits Add <bits/indirect-return.h> 2018-07-24 07:55:47 -07:00
catgets intl/tst-gettext: fix failure with newest msgfmt 2018-02-18 18:16:05 +01:00
ChangeLog.old Add missing reference to bug 21654 2017-10-07 13:14:36 +02:00
conform conform: XFAIL siginfo_t si_band test on sparc64 2018-10-26 09:19:40 +02:00
crypt New configure option --disable-crypt. 2018-06-29 16:53:47 +02:00
csu Build csu/elf-init.c and csu/static-reloc.c with stack protector 2018-07-05 22:57:45 +02:00
ctype Use libc_hidden_* for tolower, toupper (bug 15105). 2018-02-23 13:54:53 +00:00
debug Compile debug/stack_chk_fail_local.c with stack protector 2018-07-05 19:28:35 +02:00
dirent Consolidate alphasort{64} and versionsort{64} implementation 2018-04-23 17:35:16 -03:00
dlfcn malloc: tcache double free check 2018-11-28 15:45:42 -05:00
elf RISC-V: properly terminate call chain (bug 23125) 2018-12-15 21:57:43 +01:00
gmon Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
gnulib Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
grp [BZ #20271] Add newlines in __libc_fatal calls. 2018-11-09 10:17:07 -05:00
gshadow Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
hesiod Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
htl hurd: Add missing symbols for proper libc_get/setspecific 2018-08-08 02:17:39 +02:00
hurd hurd: Fix exec usage of mach_setup_thread 2018-08-01 00:10:03 +02:00
iconv Fix s390 -Os iconv build. 2018-03-05 21:46:55 +00:00
iconvdata Fix out-of-bounds access in IBM-1390 converter (bug 23448) 2018-07-24 16:45:46 +02:00
include Fix _dl_profile_fixup data-dependency issue (Bug 23690) 2018-12-07 09:05:49 -05:00
inet inet/tst-if_index-long: New test case for CVE-2018-19591 [BZ #23927] 2018-12-12 12:04:12 +01:00
intl intl: Do not return NULL on asprintf failure in gettext [BZ #24018] 2019-01-02 16:46:12 +01:00
io Avoid insecure usage of tmpnam in tests. 2018-07-18 21:04:12 +00:00
libio Increase timeout of libio/tst-readline 2018-11-19 14:21:24 +01:00
locale Fix out of bounds access in findidxwc (bug 23442) 2018-07-25 10:50:03 +02:00
localedata kl_GL: Fix spelling of Sunday, should be "sapaat" (bug 20209). 2018-10-09 00:50:20 +02:00
login Fix Linux fcntl OFD locks for non-LFS architectures (BZ#20251) 2018-06-26 13:22:53 -03:00
mach hurd: Fix exec usage of mach_setup_thread 2018-08-01 00:10:03 +02:00
malloc malloc: Always call memcpy in _int_realloc [BZ #24027] 2019-01-01 10:46:55 +01:00
manual malloc: tcache double free check 2018-11-28 15:45:42 -05:00
math Add XFAIL_ROUNDING_IBM128_LIBGCC to more fma() tests 2019-01-16 15:55:23 -02:00
mathvec Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
misc Fix misreported errno on preadv2/pwritev2 (BZ#23579) 2018-09-28 15:32:43 -03:00
nis nisplus: Correct pwent parsing issue and resulting build error [BZ #23266] 2018-06-27 21:12:16 +01:00
nptl Fix rwlock stall with PREFER_WRITER_NONRECURSIVE_NP (bug 23861) 2018-12-13 11:58:04 -05:00
nptl_db nptl_db: Remove stale match_pid' parameter from iterate_thread_list' 2018-03-01 16:10:05 +00:00
nscd [BZ #20271] Add newlines in __libc_fatal calls. 2018-11-09 10:17:07 -05:00
nss [BZ #20271] Add newlines in __libc_fatal calls. 2018-11-09 10:17:07 -05:00
po Synchronize translation project PO files. 2018-08-01 01:01:42 -04:00
posix regex: Add test tst-regcomp-truncated [BZ #23578] 2018-08-28 21:55:13 +02:00
pwd manual: Revise crypt.texi. 2018-06-29 16:53:37 +02:00
resolv Add an additional test to resolv/tst-resolv-network.c 2018-11-09 14:38:21 +01:00
resource resource/tst-getrlimit.c: Add copyright header 2018-01-05 20:34:10 +01:00
rt hurd: Add hurd thread library 2018-04-02 01:44:14 +02:00
scripts Use binutils 2.31 branch in build-many-glibcs.py. 2018-07-20 16:11:15 +00:00
setjmp x86: Use pad in pthread_unwind_buf to preserve shadow stack register 2018-05-02 06:17:41 -07:00
shadow manual: Revise crypt.texi. 2018-06-29 16:53:37 +02:00
signal Add tst-sigaction.c to test BZ #23069 2018-04-26 22:21:13 +02:00
socket Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
soft-fp Make powerpc-nofpu __sqrtsf2, __sqrtdf2 compat symbols (bug 18473). 2018-06-01 17:25:12 +00:00
stdio-common Avoid insecure usage of tmpnam in tests. 2018-07-18 21:04:12 +00:00
stdlib stdlib/tst-strtod-overflow: Switch to support_blob_repeat 2018-11-02 10:47:16 +01:00
streams Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
string Only build libm with -fno-math-errno (bug 24024) 2019-01-08 21:06:25 +01:00
sunrpc libc: Extend __libc_freeres framework (Bug 23329). 2018-06-29 22:39:06 -04:00
support support: Do not require overflow builtin in support/blob_repeat.c 2018-12-15 19:09:25 +01:00
sysdeps x86-64 memcmp/wmemcmp: Properly handle the length parameter [BZ #24097] 2019-02-01 12:19:20 -08:00
sysvipc Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
termios Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
time Fix tzfile low-memory assertion failure 2018-11-09 10:17:13 -05:00
timezone Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
wcsmbs Add tests for sign of NaN returned by strtod (bug 23007). 2018-06-15 17:36:21 +00:00
wctype Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
.gitattributes
.gitignore
abi-tags Remove the bulk of the NaCl port. 2017-05-20 08:09:10 -04:00
aclocal.m4 LIBC_SLIBDIR_RTLDDIR: substitute arguments in single quotes 2018-01-25 17:20:28 +01:00
ChangeLog x86-64 memcmp/wmemcmp: Properly handle the length parameter [BZ #24097] 2019-02-01 12:19:20 -08:00
config.h.in Switch IDNA implementation to libidn2 [BZ #19728] [BZ #19729] [BZ #22247] 2018-05-23 15:27:24 +02:00
config.make.in New configure option --disable-crypt. 2018-06-29 16:53:47 +02:00
configure x86: Support IBT and SHSTK in Intel CET [BZ #21598] 2018-07-16 14:08:27 -07:00
configure.ac x86: Support IBT and SHSTK in Intel CET [BZ #21598] 2018-07-16 14:08:27 -07:00
COPYING
COPYING.LIB
extra-lib.mk
gen-locales.mk Improve gen-locales.mk and gen-locale.sh to make test files with @ options work 2018-02-27 17:01:57 +01:00
INSTALL Update tooling versions verified to work with glibc. 2018-07-31 16:37:07 -04:00
libc-abis libc-abis: Define ABSOLUTE ABI [BZ #19818][BZ #23307] 2018-07-05 18:06:43 +01:00
libof-iterator.mk
LICENSES stdio-common/tst-printf.c: Remove part under a non-free license [BZ #23363] 2018-07-03 18:29:16 +02:00
MAINTAINERS
Makeconfig Only build libm with -fno-math-errno (bug 24024) 2019-01-08 21:06:25 +01:00
Makefile testrun.sh: Implement --tool=strace, --tool=valgrind 2018-07-04 15:30:45 +02:00
Makefile.in
Makerules Run thread shutdown functions in an explicit order 2018-06-26 15:27:12 +02:00
NEWS x86-64 memchr/wmemchr: Properly handle the length parameter [BZ #24097] 2019-02-01 12:17:27 -08:00
o-iterator.mk
README Remove tilegx port. 2018-04-27 19:11:24 +00:00
Rules Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
shlib-versions Extend NSS test suite 2017-07-17 15:52:44 -04:00
test-skeleton.c Update copyright dates with scripts/update-copyrights. 2018-01-01 00:32:25 +00:00
version.h Update NEWS, version.h, and features.h for glibc 2.28. 2018-08-01 01:10:47 -04:00

This directory contains the sources of the GNU C Library.
See the file "version.h" for what release version you have.

The GNU C Library is the standard system C library for all GNU systems,
and is an important part of what makes up a GNU system.  It provides the
system API for all programs written in C and C-compatible languages such
as C++ and Objective C; the runtime facilities of other programming
languages use the C library to access the underlying operating system.

In GNU/Linux systems, the C library works with the Linux kernel to
implement the operating system behavior seen by user applications.
In GNU/Hurd systems, it works with a microkernel and Hurd servers.

The GNU C Library implements much of the POSIX.1 functionality in the
GNU/Hurd system, using configurations i[4567]86-*-gnu.

When working with Linux kernels, this version of the GNU C Library
requires Linux kernel version 3.2 or later.

Also note that the shared version of the libgcc_s library must be
installed for the pthread library to work correctly.

The GNU C Library supports these configurations for using Linux kernels:

	aarch64*-*-linux-gnu
	alpha*-*-linux-gnu
	arm-*-linux-gnueabi
	hppa-*-linux-gnu
	i[4567]86-*-linux-gnu
	x86_64-*-linux-gnu	Can build either x86_64 or x32
	ia64-*-linux-gnu
	m68k-*-linux-gnu
	microblaze*-*-linux-gnu
	mips-*-linux-gnu
	mips64-*-linux-gnu
	powerpc-*-linux-gnu	Hardware or software floating point, BE only.
	powerpc64*-*-linux-gnu	Big-endian and little-endian.
	s390-*-linux-gnu
	s390x-*-linux-gnu
	riscv64-*-linux-gnu
	sh[34]-*-linux-gnu
	sparc*-*-linux-gnu
	sparc64*-*-linux-gnu

If you are interested in doing a port, please contact the glibc
maintainers; see http://www.gnu.org/software/libc/ for more
information.

See the file INSTALL to find out how to configure, build, and install
the GNU C Library.  You might also consider reading the WWW pages for
the C library at http://www.gnu.org/software/libc/.

The GNU C Library is (almost) completely documented by the Texinfo manual
found in the `manual/' subdirectory.  The manual is still being updated
and contains some known errors and omissions; we regret that we do not
have the resources to work on the manual as much as we would like.  For
corrections to the manual, please file a bug in the `manual' component,
following the bug-reporting instructions below.  Please be sure to check
the manual in the current development sources to see if your problem has
already been corrected.

Please see http://www.gnu.org/software/libc/bugs.html for bug reporting
information.  We are now using the Bugzilla system to track all bug reports.
This web page gives detailed information on how to report bugs properly.

The GNU C Library is free software.  See the file COPYING.LIB for copying
conditions, and LICENSES for notices about a few contributions that require
these additional notices to be distributed.  License copyright years may be
listed using range notation, e.g., 1996-2015, indicating that every year in
the range, inclusive, is a copyrightable year that would otherwise be listed
individually.