mirror of
https://github.com/nginx/nginx.git
synced 2026-08-28 12:45:21 +00:00
prevent overflow in array and list allocation size calculations
This commit is contained in:
parent
920dc099c1
commit
f339e8eebf
4 changed files with 116 additions and 21 deletions
|
|
@ -28,9 +28,24 @@ void *ngx_array_push(ngx_array_t *a);
|
|||
void *ngx_array_push_n(ngx_array_t *a, ngx_uint_t n);
|
||||
|
||||
|
||||
static ngx_inline ngx_int_t
|
||||
ngx_array_calc_size(ngx_uint_t n, size_t size, size_t *total)
|
||||
{
|
||||
if (size && n > NGX_MAX_SIZE_T_VALUE / size) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
*total = (size_t) n * size;
|
||||
|
||||
return NGX_OK;
|
||||
}
|
||||
|
||||
|
||||
static ngx_inline ngx_int_t
|
||||
ngx_array_init(ngx_array_t *array, ngx_pool_t *pool, ngx_uint_t n, size_t size)
|
||||
{
|
||||
size_t alloc;
|
||||
|
||||
/*
|
||||
* set "array->nelts" before "array->elts", otherwise MSVC thinks
|
||||
* that "array->nelts" may be used without having been initialized
|
||||
|
|
@ -41,7 +56,11 @@ ngx_array_init(ngx_array_t *array, ngx_pool_t *pool, ngx_uint_t n, size_t size)
|
|||
array->nalloc = n;
|
||||
array->pool = pool;
|
||||
|
||||
array->elts = ngx_palloc(pool, n * size);
|
||||
if (ngx_array_calc_size(n, size, &alloc) != NGX_OK) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
array->elts = ngx_palloc(pool, alloc);
|
||||
if (array->elts == NULL) {
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue