From 57aa813c733edec3ba458d8703b2d173f213757b Mon Sep 17 00:00:00 2001 From: Alejandro Colomar Date: Thu, 11 Jan 2024 12:15:11 +0100 Subject: [PATCH] lib/idmapping.c: get_map_ranges(): Move range check to a2ul() call Link: Cc: Serge Hallyn Signed-off-by: Alejandro Colomar --- lib/idmapping.c | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/lib/idmapping.c b/lib/idmapping.c index a4a4b681..da3ceefb 100644 --- a/lib/idmapping.c +++ b/lib/idmapping.c @@ -68,7 +68,10 @@ struct map_range *get_map_ranges(int ranges, int argc, char **argv) free(mappings); return NULL; } - if (a2ul(&m->count, argv[argidx + 2], NULL, 0, 0, UINT_MAX) == -1) { + if (a2ul(&m->count, argv[argidx + 2], NULL, 0, 0, + MIN(UINT_MAX - m->lower, UINT_MAX - m->upper)) + == -1) + { if (errno == ERANGE) { fprintf(log_get_logfd(), _( "%s: subuid overflow detected.\n"), log_get_progname()); exit(EXIT_FAILURE); @@ -80,10 +83,6 @@ struct map_range *get_map_ranges(int ranges, int argc, char **argv) fprintf(log_get_logfd(), _( "%s: subuid overflow detected.\n"), log_get_progname()); exit(EXIT_FAILURE); } - if (m->lower + m->count > UINT_MAX || m->upper + m->count > UINT_MAX) { - fprintf(log_get_logfd(), _( "%s: subuid overflow detected.\n"), log_get_progname()); - exit(EXIT_FAILURE); - } if (m->lower + m->count < m->lower || m->upper + m->count < m->upper) { /* this one really shouldn't be possible given previous checks */ fprintf(log_get_logfd(), _( "%s: subuid overflow detected.\n"), log_get_progname());