Module Name:    src
Committed By:   riz
Date:           Thu Dec  9 04:14:46 UTC 2010

Modified Files:
        src/lib/libc/rpc [netbsd-5]: xdr_rec.c

Log Message:
Pull up following revision(s) (requested by dholland in ticket #1493):
        lib/libc/rpc/xdr_rec.c: revision 1.31
PR/44132: Wolfgang Stukenbrock: libc/rpc may overwrite not-allocated memory
Return XPRT_DIED when realloc fails for lack of a better error.


To generate a diff of this commit:
cvs rdiff -u -r1.29 -r1.29.4.1 src/lib/libc/rpc/xdr_rec.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: src/lib/libc/rpc/xdr_rec.c
diff -u src/lib/libc/rpc/xdr_rec.c:1.29 src/lib/libc/rpc/xdr_rec.c:1.29.4.1
--- src/lib/libc/rpc/xdr_rec.c:1.29	Sun Aug 17 10:50:50 2008
+++ src/lib/libc/rpc/xdr_rec.c	Thu Dec  9 04:14:46 2010
@@ -1,4 +1,4 @@
-/*	$NetBSD: xdr_rec.c,v 1.29 2008/08/17 10:50:50 rtr Exp $	*/
+/*	$NetBSD: xdr_rec.c,v 1.29.4.1 2010/12/09 04:14:46 riz Exp $	*/
 
 /*
  * Sun RPC is a product of Sun Microsystems, Inc. and is provided for
@@ -35,7 +35,7 @@
 static char *sccsid = "@(#)xdr_rec.c 1.21 87/08/11 Copyr 1984 Sun Micro";
 static char *sccsid = "@(#)xdr_rec.c	2.2 88/08/01 4.0 RPCSRC";
 #else
-__RCSID("$NetBSD: xdr_rec.c,v 1.29 2008/08/17 10:50:50 rtr Exp $");
+__RCSID("$NetBSD: xdr_rec.c,v 1.29.4.1 2010/12/09 04:14:46 riz Exp $");
 #endif
 #endif
 
@@ -581,8 +581,12 @@
 			return FALSE;
 		}
 		rstrm->in_reclen += fraglen;
-		if (rstrm->in_reclen > rstrm->recvsize)
-			realloc_stream(rstrm, rstrm->in_reclen);
+		if ((u_int)rstrm->in_reclen > rstrm->recvsize) {
+			if (!realloc_stream(rstrm, rstrm->in_reclen)) {
+				*statp = XPRT_DIED;
+				return FALSE;
+			}
+		}
 		if (rstrm->in_header & LAST_FRAG) {
 			rstrm->in_header &= ~LAST_FRAG;
 			rstrm->last_frag = TRUE;

Reply via email to