From: Ismail Ramzi <[email protected]>

* src/unexpand.c (unexpand): Clamp a negative c32width() to 1 when
accumulating a blank, matching the sibling non-blank path and expand
and fold.  A separator whose display width is negative (e.g. U+0085
where c32issep() accepts it) left 'column' un-advanced, so the pending
blank buffer, sized for one byte of advance per blank, grew without
bound.
* NEWS: Mention the bug fix.

Link: https://github.com/coreutils/coreutils/pull/361
---
 NEWS           | 5 +++++
 src/unexpand.c | 3 ++-
 2 files changed, 7 insertions(+), 1 deletion(-)

diff --git a/NEWS b/NEWS
index 6f54390a7..85ba2cec2 100644
--- a/NEWS
+++ b/NEWS
@@ -9,6 +9,11 @@ GNU coreutils NEWS                                    -*- 
outline -*-
   resolves to a path beginning with the symbolic link itself.
   [bug introduced in coreutils-9.0]
 
+  'unexpand' no longer overflows a heap buffer on non-GLIBC platforms,
+  given whitespace characters whose display width is negative.  E.g.,
+  this edge case can occur with \u0085 (next line) characters on musl.
+  [bug introduced in coreutils-9.11]
+
   'wc' no longer miscounts characters or words when a multi-byte character
   spans input buffers.  E.g. this could affect character counts
   in GB18030 locales, and word counts in UTF-8 locales.
diff --git a/src/unexpand.c b/src/unexpand.c
index 6a9881c21..630be3613 100644
--- a/src/unexpand.c
+++ b/src/unexpand.c
@@ -199,7 +199,8 @@ unexpand (void)
                         }
                       else
                         {
-                          column += c32width (g.ch);
+                          int width = c32width (g.ch);
+                          column += width < 0 ? 1 : width;
 
                           if (! (prev_blank && column >= next_tab_column))
                             {
-- 
2.55.0


Reply via email to