Fix heap-use-after-free in pmem_realloc

realloc() frees the old block when it moves the allocation. hdr->subsystem
was read after the realloc call, from potentially freed memory. Save it to
old_subsystem before the call, matching the existing pattern for old_size.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Levi Neely 2026-03-10 12:55:06 +01:00
parent 0c0c6855c1
commit dd861f30fb
1 changed files with 4 additions and 3 deletions

View File

@ -118,13 +118,14 @@ void *pmem_realloc(pmem_subsystem_t subsystem, void *ptr, size_t size) {
hdr = ((pmem_header_t *)ptr) - 1;
old_size = hdr->size;
pmem_subsystem_t old_subsystem = hdr->subsystem;
new_hdr = (pmem_header_t *)realloc(hdr, total_size);
if (!new_hdr) {
return NULL;
}
__atomic_sub_fetch(&subsystem_stats[hdr->subsystem], old_size, __ATOMIC_RELAXED);
__atomic_sub_fetch(&subsystem_stats[old_subsystem], old_size, __ATOMIC_RELAXED);
__atomic_add_fetch(&subsystem_stats[subsystem], size, __ATOMIC_RELAXED);
new_hdr->size = size;