File: calloc-overflow.c

package info (click to toggle)
valgrind 1%3A3.24.0-3
  • links: PTS, VCS
  • area: main
  • in suites: trixie
  • size: 176,332 kB
  • sloc: ansic: 795,029; exp: 26,134; xml: 23,472; asm: 14,393; cpp: 9,397; makefile: 7,464; sh: 6,122; perl: 5,446; python: 1,498; javascript: 981; awk: 166; csh: 1
file content (20 lines) | stat: -rw-r--r-- 564 bytes parent folder | download | duplicates (11)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
#include <stdlib.h>
#include <stdio.h>
#include "pub_tool_basics.h"

int main(void)
{
   // The n*size multiplication overflows in this example.  The only sensible
   // thing to do is return NULL, but old versions of Valgrind didn't (they
   // often ground to a halt trying to allocate an enormous (but not as
   // enormous as asked-for!) block.  See bug 149878.
   int* x;
#if VG_WORDSIZE == 8
   size_t szB = 0x1000000010000001ULL;
#else
   size_t szB = 0x10000001UL;
#endif
   x = calloc(szB, 0x10);
   fprintf(stderr, "x = %#lx\n", (long)x);
   return 0;
}