diff options
| author | Paul Eggert <eggert@cs.ucla.edu> | 2021-09-13 22:49:45 -0700 |
|---|---|---|
| committer | Florian Weimer <fweimer@redhat.com> | 2022-01-07 10:20:02 +0100 |
| commit | 515a6f53cd984d5e6e374fbee52772f967fc3c73 (patch) | |
| tree | f841d7c9622918d06535c6085db580d7e2f0c66a | |
| parent | 217b84127b3a6590afcc7e198e6c3f665935e8f4 (diff) | |
| download | glibc-515a6f53cd984d5e6e374fbee52772f967fc3c73.tar.xz glibc-515a6f53cd984d5e6e374fbee52772f967fc3c73.zip | |
Fix subscript error with odd TZif file [BZ #28338]
* time/tzfile.c (__tzfile_compute): Fix unlikely off-by-one bug
that accessed before start of an array when an oddball-but-valid
TZif file was queried with an unusual time_t value.
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
(cherry picked from commit 645277434a42efc547d2cac8bfede4da10b4049f)
| -rw-r--r-- | NEWS | 3 | ||||
| -rw-r--r-- | time/tzfile.c | 3 |
2 files changed, 3 insertions, 3 deletions
@@ -15,13 +15,14 @@ The following bugs are resolved with this release: [28182] _TIME_BITS=64 in C++ has issues with fcntl, ioctl, prctl [28223] mips: clone does not align stack [28310] Do not use affinity mask for sysconf (_SC_NPROCESSORS_CONF) + [28338] undefined behavior in __tzfile_compute with oddball TZif file [28340] ld.so crashes while loading a DSO with a read-only dynamic section [28357] deadlock between pthread_create and ELF constructors [28361] nptl: Avoid setxid deadlock with blocked signals in thread exit [28407] pthread_kill assumes that kill and tgkill are equivalent [28524] Conversion from ISO-2022-JP-3 with iconv may emit spurious NULs - [28607] Masked signals are delivered on thread exit [28532] powerpc64[le]: CFI for assembly templated syscalls is incorrect + [28607] Masked signals are delivered on thread exit [28678] nptl/tst-create1 hangs sporadically [28700] "dns [!UNAVAIL=return] files" NSS default for hosts is not useful [28702] RISC-V: clone does not align stack diff --git a/time/tzfile.c b/time/tzfile.c index 4377018a55..190a777152 100644 --- a/time/tzfile.c +++ b/time/tzfile.c @@ -765,8 +765,7 @@ __tzfile_compute (__time64_t timer, int use_localtime, *leap_correct = leaps[i].change; if (timer == leaps[i].transition /* Exactly at the transition time. */ - && ((i == 0 && leaps[i].change > 0) - || leaps[i].change > leaps[i - 1].change)) + && (leaps[i].change > (i == 0 ? 0 : leaps[i - 1].change))) { *leap_hit = 1; while (i > 0 |
