This is the mail archive of the
glibc-bugs@sourceware.org
mailing list for the glibc project.
[Bug malloc/19449] malloc.c fastbin_index(),smallbin_index() type conversion error
- From: "scwuaptx at gmail dot com" <sourceware-bugzilla at sourceware dot org>
- To: glibc-bugs at sourceware dot org
- Date: Tue, 12 Jan 2016 20:51:12 +0000
- Subject: [Bug malloc/19449] malloc.c fastbin_index(),smallbin_index() type conversion error
- Auto-submitted: auto-generated
- References: <bug-19449-131 at http dot sourceware dot org/bugzilla/>
https://sourceware.org/bugzilla/show_bug.cgi?id=19449
--- Comment #2 from An-jie Yang <scwuaptx at gmail dot com> ---
(In reply to Andreas Schwab from comment #1)
> The argument is never bigger than MAX_FAST_SIZE.
But if something corruption the chunk of the fastbin ,it will bypass the check
of index easy.
For example,if the fd in the chunk be modified to point to somewhere , it only
satisfy the 4 byte size in the 64bit system.
--
You are receiving this mail because:
You are on the CC list for the bug.