From 01b3cded76daacbfddb7f8763700b0803bcb5c6f Mon Sep 17 00:00:00 2001 From: itchyny Date: Fri, 24 Apr 2026 22:09:44 +0900 Subject: [PATCH] Fix signed-int overflow in `stack_reallocate` This fixes CVE-2026-41257. CVE: CVE-2026-41257 Upstream: https://github.com/jqlang/jq/commit/01b3cded76daacbfddb7f8763700b0803bcb5c6f Signed-off-by: Thomas Perale --- src/exec_stack.h | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/src/exec_stack.h b/src/exec_stack.h index 2a063e8cf9..159c56e4fb 100644 --- a/src/exec_stack.h +++ b/src/exec_stack.h @@ -2,8 +2,10 @@ #define EXEC_STACK_H #include #include +#include #include #include +#include #include "jv_alloc.h" /* @@ -81,15 +83,19 @@ static stack_ptr* stack_block_next(struct stack* s, stack_ptr p) { } static void stack_reallocate(struct stack* s, size_t sz) { - int old_mem_length = -(s->bound) + ALIGNMENT; - char* old_mem_start = (s->mem_end != NULL) ? (s->mem_end - old_mem_length) : NULL; + size_t old_mem_length = (size_t)(-(s->bound)) + ALIGNMENT; + char* old_mem_start = s->mem_end != NULL ? s->mem_end - old_mem_length : NULL; - int new_mem_length = align_round_up((old_mem_length + sz + 256) * 2); + size_t new_mem_length = align_round_up((old_mem_length + sz + 256) * 2); + if (new_mem_length > INT_MAX) { + fprintf(stderr, "jq: error: cannot allocate memory\n"); + abort(); + } char* new_mem_start = jv_mem_realloc(old_mem_start, new_mem_length); memmove(new_mem_start + (new_mem_length - old_mem_length), new_mem_start, old_mem_length); s->mem_end = new_mem_start + new_mem_length; - s->bound = -(new_mem_length - ALIGNMENT); + s->bound = -(int)(new_mem_length - ALIGNMENT); } static stack_ptr stack_push_block(struct stack* s, stack_ptr p, size_t sz) {