Tcl Source Code

View Ticket
Login
Ticket UUID: 77059c4f456952a4a7c23392b7a9a8d200bbcc39
Title: TclPushVarName(): pointer overflow
Type: Bug Created on: 2023-05-08 20:05:19
Submitter: chrstphrchvz Assigned to: jan.nijtmans
Subsystem: 07. Variables Severity: Minor
Priority: 5 Medium Last modified: 2025-09-19 17:08:26
Status: Closed Closed by: jan.nijtmans
Resolution: Fixed Closed on: 2025-09-19 17:08:26
Version: core-9-0-branch
Description:

Doing set {} (e.g. from var-6.3) triggers an -fsanitize=pointer-overflow error:

generic/tclCompCmds.c:3454:6: runtime error: addition of unsigned offset to 0x603000023a75 overflowed to 0x603000023a74
This might seem due to nameLen now being size_t, but I think it would be better if there was a check for nameLen < 1 or < 2.

User Comments:
chrstphrchvz added on 2025-09-17 23:20:17:

A better possible fix might be to declare nameLen as Tcl_Size.


jan.nijtmans added on 2025-09-18 09:38:10:

Like [1a3e5bdaf5|this]?


chrstphrchvz added on 2025-09-18 18:08:09:

I had thought of using Tcl_Size in case the current behavior was correct and that the overflow was harmless. But looking again, I see how the overflow suggests there is a problem, so I agree with Jan proposed's fix.


jan.nijtmans added on 2025-09-19 17:08:26:

Fixed [ef820cf3b7e15fc3|here] (and in all other branches as well)

Thanks!