Blame SOURCES/0387-util-grub-editenv-Fix-incorrect-casting-of-a-signed-.patch

b1bcb2
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
b1bcb2
From: Darren Kenny <darren.kenny@oracle.com>
b1bcb2
Date: Thu, 5 Nov 2020 14:33:50 +0000
b1bcb2
Subject: [PATCH] util/grub-editenv: Fix incorrect casting of a signed value
b1bcb2
b1bcb2
The return value of ftell() may be negative (-1) on error. While it is
b1bcb2
probably unlikely to occur, we should not blindly cast to an unsigned
b1bcb2
value without first testing that it is not negative.
b1bcb2
b1bcb2
Fixes: CID 73856
b1bcb2
b1bcb2
Signed-off-by: Darren Kenny <darren.kenny@oracle.com>
b1bcb2
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
b1bcb2
---
b1bcb2
 util/grub-editenv.c | 8 +++++++-
b1bcb2
 1 file changed, 7 insertions(+), 1 deletion(-)
b1bcb2
b1bcb2
diff --git a/util/grub-editenv.c b/util/grub-editenv.c
b1bcb2
index 118e89fe57f..9fff221b181 100644
b1bcb2
--- a/util/grub-editenv.c
b1bcb2
+++ b/util/grub-editenv.c
b1bcb2
@@ -125,6 +125,7 @@ open_envblk_file (const char *name)
b1bcb2
 {
b1bcb2
   FILE *fp;
b1bcb2
   char *buf;
b1bcb2
+  long loc;
b1bcb2
   size_t size;
b1bcb2
   grub_envblk_t envblk;
b1bcb2
 
b1bcb2
@@ -143,7 +144,12 @@ open_envblk_file (const char *name)
b1bcb2
     grub_util_error (_("cannot seek `%s': %s"), name,
b1bcb2
 		     strerror (errno));
b1bcb2
 
b1bcb2
-  size = (size_t) ftell (fp);
b1bcb2
+  loc = ftell (fp);
b1bcb2
+  if (loc < 0)
b1bcb2
+    grub_util_error (_("cannot get file location `%s': %s"), name,
b1bcb2
+		     strerror (errno));
b1bcb2
+
b1bcb2
+  size = (size_t) loc;
b1bcb2
 
b1bcb2
   if (fseek (fp, 0, SEEK_SET) < 0)
b1bcb2
     grub_util_error (_("cannot seek `%s': %s"), name,