From dea3c2e1aa1b775baa690b9ef40239f881c5f068 Mon Sep 17 00:00:00 2001 From: Khem Raj Date: Wed, 13 Aug 2025 20:23:48 -0700 Subject: [PATCH] vsnprintf_s: Increase Buffer Size by 1 It is a buffer overflow warning that GCC 15.2 is catching. The issue is that it's trying to write to `buf[len++]` when len could potentially be 31, which would write to buf[31] in a buffer of size 32 (valid indices 0-31), but the len++ post-increment means it could theoretically write beyond the buffer bounds. Fixes ../../sources/safec-3.9.1/src/str/vsnprintf_s.c: In function 'safec_ftoa.isra': ../../sources/safec-3.9.1/src/str/vsnprintf_s.c:523:24: error: writing 32 bytes into a region of size 31 [-Werror=stringop-overflow=] 523 | buf[len++] = '0'; | ~~~~~~~~~~~^~~~~ ../../sources/safec-3.9.1/src/str/vsnprintf_s.c:394:10: note: at offset [1, 32] into destination object 'buf' of size 32 394 | char buf[PRINTF_FTOA_BUFFER_SIZE]; | ^~~ cc1: all warnings being treated as errors Upstream-Status: Submitted [https://github.com/rurban/safeclib/pull/148] Signed-off-by: Khem Raj Upstream: https://github.com/rurban/safeclib/commit/f59a0c8c1b5cf19cd0ed7f9bfb3a1e85f54113d0 [backported to version 3.7.1] Signed-off-by: Bernd Kuhls --- src/str/vsnprintf_s.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/str/vsnprintf_s.c b/src/str/vsnprintf_s.c index ca838df1..8ef6989a 100644 --- a/src/str/vsnprintf_s.c +++ b/src/str/vsnprintf_s.c @@ -369,7 +369,7 @@ static size_t safec_ftoa(out_fct_type out, const char *funcname, double value, unsigned int prec, unsigned int width, unsigned int flags) { - char buf[PRINTF_FTOA_BUFFER_SIZE]; + char buf[PRINTF_FTOA_BUFFER_SIZE + 1]; size_t len = 0U; double tmp; double diff = 0.0; -- 2.47.3