Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Validate claim that CVE-2022-39377 and CVE-2023-33204 affect 32-bit systems only

Offen
#403 5 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
25/100
Issue-Typ
Dokumentation
Klarheit
Größtenteils klar
Aktivitätsstatus
Veraltet
Tech-Stack
c

Rechercherichtung

Start with the linked security advisory, GHSA-q8r6-g56f-9w7x, and examine the reported multiplication of three integer-derived factors in the affected code. Determine whether the overflow is limited to 32-bit systems or can also occur on 64-bit systems. Done means the advisory's claim is supported with an explanation or corrected to reflect the findings.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Regarding your helpful advisory at:

https://github.com/sysstat/sysstat/security/advisories/GHSA-q8r6-g56f-9w7x

You claim that the overflow is only present on 32-bit systems. I assume this has to do with the size_t type being 32-bit.

However, there's multiplication of 3 factors, each of which comes from a field of type int (or __nr_t, which is also int). With arbitrary 3 int factors, even 64-bit size_t can overflow.

Do you know of a specific reason why this can't happen (if so, I suggest you add this to the advisory), or is the claim that the issue is limited to 32-bit systems wrong (in which case the advisory should be edited to remove that claim and mention the error of its earlier revision), or is this not actually known?

Vorherrschende Sprache
C
Sterne
3.4k
Forks
490
Ø Merge
3 T. 14 Std.
Gemergte PRs (30 T.)
5

Entwicklungsumgebung

Dieses Projekt bietet weder Dev-Container noch Dockerfile noch Beitragsleitfaden – die Einrichtung liegt bei Ihnen. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus sysstat/sysstat

Alle Issues in sysstat/sysstat

Ähnliche Issues

Weitere Issues zu C

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.