!243 gconv: Do not emit spurious NUL character in ISO-2022-JP-3
From: @liqingqing_1229 Reviewed-by: @wswsamao Signed-off-by: @wswsamao
This commit is contained in:
commit
8688e5e637
185
gconv-Do-not-emit-spurious-NUL-character-in-ISO-2022.patch
Normal file
185
gconv-Do-not-emit-spurious-NUL-character-in-ISO-2022.patch
Normal file
@ -0,0 +1,185 @@
|
|||||||
|
From ff012870b2c02a62598c04daa1e54632e020fd7d Mon Sep 17 00:00:00 2001
|
||||||
|
From: Nikita Popov <npv1310@gmail.com>
|
||||||
|
Date: Tue, 2 Nov 2021 13:21:42 +0500
|
||||||
|
Subject: [PATCH] gconv: Do not emit spurious NUL character in ISO-2022-JP-3
|
||||||
|
(bug 28524)
|
||||||
|
|
||||||
|
Bugfix 27256 has introduced another issue:
|
||||||
|
In conversion from ISO-2022-JP-3 encoding, it is possible
|
||||||
|
to force iconv to emit extra NUL character on internal state reset.
|
||||||
|
To do this, it is sufficient to feed iconv with escape sequence
|
||||||
|
which switches active character set.
|
||||||
|
The simplified check 'data->__statep->__count != ASCII_set'
|
||||||
|
introduced by the aforementioned bugfix picks that case and
|
||||||
|
behaves as if '\0' character has been queued thus emitting it.
|
||||||
|
|
||||||
|
To eliminate this issue, these steps are taken:
|
||||||
|
* Restore original condition
|
||||||
|
'(data->__statep->__count & ~7) != ASCII_set'.
|
||||||
|
It is necessary since bits 0-2 may contain
|
||||||
|
number of buffered input characters.
|
||||||
|
* Check that queued character is not NUL.
|
||||||
|
Similar step is taken for main conversion loop.
|
||||||
|
|
||||||
|
Bundled test case follows following logic:
|
||||||
|
* Try to convert ISO-2022-JP-3 escape sequence
|
||||||
|
switching active character set
|
||||||
|
* Reset internal state by providing NULL as input buffer
|
||||||
|
* Ensure that nothing has been converted.
|
||||||
|
|
||||||
|
Signed-off-by: Nikita Popov <npv1310@gmail.com>
|
||||||
|
---
|
||||||
|
iconvdata/Makefile | 5 +++-
|
||||||
|
iconvdata/bug-iconv15.c | 60 +++++++++++++++++++++++++++++++++++++++
|
||||||
|
iconvdata/iso-2022-jp-3.c | 28 ++++++++++++------
|
||||||
|
3 files changed, 84 insertions(+), 9 deletions(-)
|
||||||
|
create mode 100644 iconvdata/bug-iconv15.c
|
||||||
|
|
||||||
|
diff --git a/iconvdata/Makefile b/iconvdata/Makefile
|
||||||
|
index c216f959..d5507a04 100644
|
||||||
|
--- a/iconvdata/Makefile
|
||||||
|
+++ b/iconvdata/Makefile
|
||||||
|
@@ -1,4 +1,5 @@
|
||||||
|
# Copyright (C) 1997-2021 Free Software Foundation, Inc.
|
||||||
|
+# Copyright (C) The GNU Toolchain Authors.
|
||||||
|
# This file is part of the GNU C Library.
|
||||||
|
|
||||||
|
# The GNU C Library is free software; you can redistribute it and/or
|
||||||
|
@@ -74,7 +75,7 @@ ifeq (yes,$(build-shared))
|
||||||
|
tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \
|
||||||
|
tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \
|
||||||
|
bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \
|
||||||
|
- bug-iconv13 bug-iconv14
|
||||||
|
+ bug-iconv13 bug-iconv14 bug-iconv15
|
||||||
|
ifeq ($(have-thread-library),yes)
|
||||||
|
tests += bug-iconv3
|
||||||
|
endif
|
||||||
|
@@ -327,6 +328,8 @@ $(objpfx)bug-iconv12.out: $(addprefix $(objpfx), $(gconv-modules)) \
|
||||||
|
$(addprefix $(objpfx),$(modules.so))
|
||||||
|
$(objpfx)bug-iconv14.out: $(addprefix $(objpfx), $(gconv-modules)) \
|
||||||
|
$(addprefix $(objpfx),$(modules.so))
|
||||||
|
+$(objpfx)bug-iconv15.out: $(addprefix $(objpfx), $(gconv-modules)) \
|
||||||
|
+ $(addprefix $(objpfx),$(modules.so))
|
||||||
|
|
||||||
|
$(objpfx)iconv-test.out: run-iconv-test.sh \
|
||||||
|
$(addprefix $(objpfx), $(gconv-modules)) \
|
||||||
|
diff --git a/iconvdata/bug-iconv15.c b/iconvdata/bug-iconv15.c
|
||||||
|
new file mode 100644
|
||||||
|
index 00000000..cc04bd03
|
||||||
|
--- /dev/null
|
||||||
|
+++ b/iconvdata/bug-iconv15.c
|
||||||
|
@@ -0,0 +1,60 @@
|
||||||
|
+/* Bug 28524: Conversion from ISO-2022-JP-3 with iconv
|
||||||
|
+ may emit spurious NUL character on state reset.
|
||||||
|
+ Copyright (C) The GNU Toolchain Authors.
|
||||||
|
+ This file is part of the GNU C Library.
|
||||||
|
+
|
||||||
|
+ The GNU C Library is free software; you can redistribute it and/or
|
||||||
|
+ modify it under the terms of the GNU Lesser General Public
|
||||||
|
+ License as published by the Free Software Foundation; either
|
||||||
|
+ version 2.1 of the License, or (at your option) any later version.
|
||||||
|
+
|
||||||
|
+ The GNU C Library is distributed in the hope that it will be useful,
|
||||||
|
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
+ Lesser General Public License for more details.
|
||||||
|
+
|
||||||
|
+ You should have received a copy of the GNU Lesser General Public
|
||||||
|
+ License along with the GNU C Library; if not, see
|
||||||
|
+ <https://www.gnu.org/licenses/>. */
|
||||||
|
+
|
||||||
|
+#include <stddef.h>
|
||||||
|
+#include <iconv.h>
|
||||||
|
+#include <support/check.h>
|
||||||
|
+
|
||||||
|
+static int
|
||||||
|
+do_test (void)
|
||||||
|
+{
|
||||||
|
+ char in[] = "\x1b(I";
|
||||||
|
+ char *inbuf = in;
|
||||||
|
+ size_t inleft = sizeof (in) - 1;
|
||||||
|
+ char out[1];
|
||||||
|
+ char *outbuf = out;
|
||||||
|
+ size_t outleft = sizeof (out);
|
||||||
|
+ iconv_t cd;
|
||||||
|
+
|
||||||
|
+ cd = iconv_open ("UTF8", "ISO-2022-JP-3");
|
||||||
|
+ TEST_VERIFY_EXIT (cd != (iconv_t) -1);
|
||||||
|
+
|
||||||
|
+ /* First call to iconv should alter internal state.
|
||||||
|
+ Now, JISX0201_Kana_set is selected and
|
||||||
|
+ state value != ASCII_set. */
|
||||||
|
+ TEST_VERIFY (iconv (cd, &inbuf, &inleft, &outbuf, &outleft) != (size_t) -1);
|
||||||
|
+
|
||||||
|
+ /* No bytes should have been added to
|
||||||
|
+ the output buffer at this point. */
|
||||||
|
+ TEST_VERIFY (outbuf == out);
|
||||||
|
+ TEST_VERIFY (outleft == sizeof (out));
|
||||||
|
+
|
||||||
|
+ /* Second call shall emit spurious NUL character in unpatched glibc. */
|
||||||
|
+ TEST_VERIFY (iconv (cd, NULL, NULL, &outbuf, &outleft) != (size_t) -1);
|
||||||
|
+
|
||||||
|
+ /* No characters are expected to be produced. */
|
||||||
|
+ TEST_VERIFY (outbuf == out);
|
||||||
|
+ TEST_VERIFY (outleft == sizeof (out));
|
||||||
|
+
|
||||||
|
+ TEST_VERIFY_EXIT (iconv_close (cd) != -1);
|
||||||
|
+
|
||||||
|
+ return 0;
|
||||||
|
+}
|
||||||
|
+
|
||||||
|
+#include <support/test-driver.c>
|
||||||
|
diff --git a/iconvdata/iso-2022-jp-3.c b/iconvdata/iso-2022-jp-3.c
|
||||||
|
index c8ba88cd..5fc0c0f7 100644
|
||||||
|
--- a/iconvdata/iso-2022-jp-3.c
|
||||||
|
+++ b/iconvdata/iso-2022-jp-3.c
|
||||||
|
@@ -1,5 +1,6 @@
|
||||||
|
/* Conversion module for ISO-2022-JP-3.
|
||||||
|
Copyright (C) 1998-2021 Free Software Foundation, Inc.
|
||||||
|
+ Copyright (C) The GNU Toolchain Authors.
|
||||||
|
This file is part of the GNU C Library.
|
||||||
|
Contributed by Ulrich Drepper <drepper@cygnus.com>, 1998,
|
||||||
|
and Bruno Haible <bruno@clisp.org>, 2002.
|
||||||
|
@@ -81,20 +82,31 @@ enum
|
||||||
|
the output state to the initial state. This has to be done during the
|
||||||
|
flushing. */
|
||||||
|
#define EMIT_SHIFT_TO_INIT \
|
||||||
|
- if (data->__statep->__count != ASCII_set) \
|
||||||
|
+ if ((data->__statep->__count & ~7) != ASCII_set) \
|
||||||
|
{ \
|
||||||
|
if (FROM_DIRECTION) \
|
||||||
|
{ \
|
||||||
|
- if (__glibc_likely (outbuf + 4 <= outend)) \
|
||||||
|
+ uint32_t ch = data->__statep->__count >> 6; \
|
||||||
|
+ \
|
||||||
|
+ if (__glibc_unlikely (ch != 0)) \
|
||||||
|
{ \
|
||||||
|
- /* Write out the last character. */ \
|
||||||
|
- *((uint32_t *) outbuf) = data->__statep->__count >> 6; \
|
||||||
|
- outbuf += sizeof (uint32_t); \
|
||||||
|
- data->__statep->__count = ASCII_set; \
|
||||||
|
+ if (__glibc_likely (outbuf + 4 <= outend)) \
|
||||||
|
+ { \
|
||||||
|
+ /* Write out the last character. */ \
|
||||||
|
+ put32u (outbuf, ch); \
|
||||||
|
+ outbuf += 4; \
|
||||||
|
+ data->__statep->__count &= 7; \
|
||||||
|
+ data->__statep->__count |= ASCII_set; \
|
||||||
|
+ } \
|
||||||
|
+ else \
|
||||||
|
+ /* We don't have enough room in the output buffer. */ \
|
||||||
|
+ status = __GCONV_FULL_OUTPUT; \
|
||||||
|
} \
|
||||||
|
else \
|
||||||
|
- /* We don't have enough room in the output buffer. */ \
|
||||||
|
- status = __GCONV_FULL_OUTPUT; \
|
||||||
|
+ { \
|
||||||
|
+ data->__statep->__count &= 7; \
|
||||||
|
+ data->__statep->__count |= ASCII_set; \
|
||||||
|
+ } \
|
||||||
|
} \
|
||||||
|
else \
|
||||||
|
{ \
|
||||||
|
--
|
||||||
|
2.23.0
|
||||||
|
|
||||||
@ -65,7 +65,7 @@
|
|||||||
##############################################################################
|
##############################################################################
|
||||||
Name: glibc
|
Name: glibc
|
||||||
Version: 2.34
|
Version: 2.34
|
||||||
Release: 22
|
Release: 23
|
||||||
Summary: The GNU libc libraries
|
Summary: The GNU libc libraries
|
||||||
License: %{all_license}
|
License: %{all_license}
|
||||||
URL: http://www.gnu.org/software/glibc/
|
URL: http://www.gnu.org/software/glibc/
|
||||||
@ -127,6 +127,7 @@ Patch40: nptl-Fix-type-of-pthread_mutexattr_getrobust_np-pthr.patch
|
|||||||
Patch41: nptl-Avoid-setxid-deadlock-with-blocked-signals-in-t.patch
|
Patch41: nptl-Avoid-setxid-deadlock-with-blocked-signals-in-t.patch
|
||||||
Patch42: nptl-pthread_kill-must-send-signals-to-a-specific-th.patch
|
Patch42: nptl-pthread_kill-must-send-signals-to-a-specific-th.patch
|
||||||
Patch43: iconvconfig-Fix-behaviour-with-prefix-BZ-28199.patch
|
Patch43: iconvconfig-Fix-behaviour-with-prefix-BZ-28199.patch
|
||||||
|
Patch44: gconv-Do-not-emit-spurious-NUL-character-in-ISO-2022.patch
|
||||||
|
|
||||||
#Patch9000: turn-REP_STOSB_THRESHOLD-from-2k-to-1M.patch
|
#Patch9000: turn-REP_STOSB_THRESHOLD-from-2k-to-1M.patch
|
||||||
Patch9001: delete-no-hard-link-to-avoid-all_language-package-to.patch
|
Patch9001: delete-no-hard-link-to-avoid-all_language-package-to.patch
|
||||||
@ -1316,6 +1317,11 @@ fi
|
|||||||
%endif
|
%endif
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Wed Nov 10 2021 Qingqing Li <liqingqing3@huawei.com> - 2.34-23
|
||||||
|
- gconv: Do not emit spurious NUL character in ISO-2022-JP-3,
|
||||||
|
this also fix CVE-2021-43396.
|
||||||
|
uplink: https://sourceware.org/bugzilla/show_bug.cgi?id=28524
|
||||||
|
|
||||||
* Tue Nov 9 2021 Qingqing Li<liqingqing3@huawei.com> - 2.34-22
|
* Tue Nov 9 2021 Qingqing Li<liqingqing3@huawei.com> - 2.34-22
|
||||||
- iconvconfig: Fix behaviour with --prefix
|
- iconvconfig: Fix behaviour with --prefix
|
||||||
uplink: https://sourceware.org/bugzilla/show_bug.cgi?id=28199
|
uplink: https://sourceware.org/bugzilla/show_bug.cgi?id=28199
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user