[Bug c/101832] __builtin_object_size(P->M, 1) where M ends with a flex-array behaves like sizeof()

kees at outflux dot net gcc-bugzilla@gcc.gnu.org
Mon Aug 9 17:10:59 GMT 2021


https://gcc.gnu.org/bugzilla/show_bug.cgi?id=101832

--- Comment #2 from Kees Cook <kees at outflux dot net> ---
Created attachment 51280
  --> https://gcc.gnu.org/bugzilla/attachment.cgi?id=51280&action=edit
Same PoC, but with malloc to provide non-unlimited bounds


More information about the Gcc-bugs mailing list