Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

The check_overflow() function can work incorrectly in some cases

Abierto
#359 4 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
25/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Estancado
Stack tecnológico
c
Área
security

Línea de trabajo

Read check_overflow() in common.c at the linked location and trace how it checks the product of its three unsigned int arguments. The issue gives two argument combinations that can expose the incorrect check; use them to assess whether the overflow is detected. Done means the check handles these cases without overflowing its intermediate calculation.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

The check_overflow() function has been implemented to check an overflow of the product of three numbers.
Here is the declaration:
void check_overflow(unsigned int val1, unsigned int val2, unsigned int val3)

Unfortunately, the implementation you can see here isn't tolerant against an arithmetic overflow at least on 64bit systems. Please, pay attention that sizeof(unsigned long long) == 8, so it can hold values no more than 2^64-1, but each of val1, val2, and val3 can hold values up to 2^32-1, so the product of (2^32-1) * (2^32-1) * (2^32-1) overflows the 64-bit variable.

However, not every overflow leads to a failing check, most cases still detect an overflow even the product has been truncated, but there are combinations of arguments when things go wrong, for example:

  • check_overflow(UINT_MAX, UINT_MAX, 2147483648),
  • check_overflow(UINT_MAX-100, UINT_MAX-5, 2849931574)
    and so on.

It seems the CVE-2022-39377 is still exploitable in some conditions.

Lenguaje dominante
C
Estrellas
3.4k
Forks
490
Merge medio
3 d 14 h
PR fusionados (30 d)
5

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de sysstat/sysstat

Todos los issues de sysstat/sysstat

Issues similares

Más issues de C

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.