File: calloc-overflow.c

package info (click to toggle)
valgrind 1%3A3.12.0~svn20160714-1
  • links: PTS, VCS
  • area: main
  • in suites: stretch
  • size: 120,428 kB
  • ctags: 70,855
  • sloc: ansic: 674,645; exp: 26,134; xml: 21,574; asm: 7,570; cpp: 7,567; makefile: 7,380; sh: 6,188; perl: 5,855; haskell: 195
file content (20 lines) | stat: -rw-r--r-- 564 bytes parent folder | download | duplicates (9)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
#include <stdlib.h>
#include <stdio.h>
#include "pub_tool_basics.h"

int main(void)
{
   // The n*size multiplication overflows in this example.  The only sensible
   // thing to do is return NULL, but old versions of Valgrind didn't (they
   // often ground to a halt trying to allocate an enormous (but not as
   // enormous as asked-for!) block.  See bug 149878.
   int* x;
#if VG_WORDSIZE == 8
   size_t szB = 0x1000000010000001ULL;
#else
   size_t szB = 0x10000001UL;
#endif
   x = calloc(szB, 0x10);
   fprintf(stderr, "x = %#lx\n", (long)x);
   return 0;
}