From: Ismail Ramzi <[email protected]> * src/unexpand.c (unexpand): Clamp a negative c32width() to 1 when accumulating a blank, matching the sibling non-blank path and expand and fold. A separator whose display width is negative (e.g. U+0085 where c32issep() accepts it) left 'column' un-advanced, so the pending blank buffer, sized for one byte of advance per blank, grew without bound. * NEWS: Mention the bug fix.
Link: https://github.com/coreutils/coreutils/pull/361 --- NEWS | 5 +++++ src/unexpand.c | 3 ++- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/NEWS b/NEWS index 6f54390a7..85ba2cec2 100644 --- a/NEWS +++ b/NEWS @@ -9,6 +9,11 @@ GNU coreutils NEWS -*- outline -*- resolves to a path beginning with the symbolic link itself. [bug introduced in coreutils-9.0] + 'unexpand' no longer overflows a heap buffer on non-GLIBC platforms, + given whitespace characters whose display width is negative. E.g., + this edge case can occur with \u0085 (next line) characters on musl. + [bug introduced in coreutils-9.11] + 'wc' no longer miscounts characters or words when a multi-byte character spans input buffers. E.g. this could affect character counts in GB18030 locales, and word counts in UTF-8 locales. diff --git a/src/unexpand.c b/src/unexpand.c index 6a9881c21..630be3613 100644 --- a/src/unexpand.c +++ b/src/unexpand.c @@ -199,7 +199,8 @@ unexpand (void) } else { - column += c32width (g.ch); + int width = c32width (g.ch); + column += width < 0 ? 1 : width; if (! (prev_blank && column >= next_tab_column)) { -- 2.55.0
