From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 From: =?utf-8?b?THVrw6HFoSBaYW9yYWwgPGx6YW9yYWxAcmVkaGF0LmNvbT4=?= To: git-commits@fedoraproject.org Subject: [rpms/coreutils] f43: unexpand: fix heap overflows Date: Thu, 11 Jun 2026 10:53:07 GMT Message-ID: <178117518730.1.9100247178732322792.rpms-coreutils-73520a03ad3a@fedoraproject.org> List-ID: X-Git-Repo: rpms/coreutils X-Git-Branch: f43 X-Git-Rev: 73520a03ad3a5783daa8b6d4005217ee874432d5 QSBuZXcgY29tbWl0IGhhcyBiZWVuIHB1c2hlZC4KClJlcG8gICA6IHJwbXMvY29yZXV0aWxzCkJy YW5jaCA6IGY0MwpDb21taXQgOiA3MzUyMGEwM2FkM2E1NzgzZGFhOGI2ZDQwMDUyMTdlZTg3NDQz MmQ1CkF1dGhvciA6IEx1a8OhxaEgWmFvcmFsIDxsemFvcmFsQHJlZGhhdC5jb20+CkRhdGUgICA6 IDIwMjYtMDYtMTFUMTI6NDY6NDYrMDI6MDAKU3RhdHMgIDogKzM4Ly0xOCBpbiAyIGZpbGUocykK VVJMICAgIDogaHR0cHM6Ly9zcmMuZmVkb3JhcHJvamVjdC5vcmcvcnBtcy9jb3JldXRpbHMvYy83 MzUyMGEwM2FkM2E1NzgzZGFhOGI2ZDQwMDUyMTdlZTg3NDQzMmQ1P2JyYW5jaD1mNDMKCkxvZzoK dW5leHBhbmQ6IGZpeCBoZWFwIG92ZXJmbG93cwoKLS0tCmRpZmYgLS1naXQgYS9jb3JldXRpbHMt aTE4bi5wYXRjaCBiL2NvcmV1dGlscy1pMThuLnBhdGNoCmluZGV4IGNjN2Q0M2EuLmViOTkzY2Eg MTAwNjQ0Ci0tLSBhL2NvcmV1dGlscy1pMThuLnBhdGNoCisrKyBiL2NvcmV1dGlscy1pMThuLnBh dGNoCkBAIC0xMCwxOCArMTAsMTggQEAgU3ViamVjdDogW1BBVENIXSBjb3JldXRpbHMtaTE4bi5w YXRjaAogIGxpYi9tYmNoYXIuYyAgICAgICAgICAgICAgICB8ICAyMyArKwogIGxpYi9tYmNoYXIu aCAgICAgICAgICAgICAgICB8IDM4MyArKysrKysrKysrKysrKysrKwogIGxpYi9tYmZpbGUuYyAg ICAgICAgICAgICAgICB8ICAyMCArCi0gbGliL21iZmlsZS5oICAgICAgICAgICAgICAgIHwgMjgz ICsrKysrKysrKysrKysKKyBsaWIvbWJmaWxlLmggICAgICAgICAgICAgICAgfCAyNzcgKysrKysr KysrKysrKwogIG00L21iY2hhci5tNCAgICAgICAgICAgICAgICB8ICAxNSArCiAgbTQvbWJmaWxl Lm00ICAgICAgICAgICAgICAgIHwgIDE2ICsKICBzcmMvY3V0LmMgICAgICAgICAgICAgICAgICAg fCA1MDggKysrKysrKysrKysrKysrKysrKysrLS0KICBzcmMvZXhwYW5kLWNvbW1vbi5jICAgICAg ICAgfCAxMTQgKysrKysrCiAgc3JjL2V4cGFuZC1jb21tb24uaCAgICAgICAgIHwgIDEyICsKICBz cmMvZXhwYW5kLmMgICAgICAgICAgICAgICAgfCAgOTAgKysrLQotIHNyYy9mb2xkLmMgICAgICAg ICAgICAgICAgICB8IDMxMSArKysrKysrKysrKystLQorIHNyYy9mb2xkLmMgICAgICAgICAgICAg ICAgICB8IDMxMiArKysrKysrKysrKystLQogIHNyYy9sb2NhbC5tayAgICAgICAgICAgICAgICB8 ICAgNCArLQogIHNyYy9wci5jICAgICAgICAgICAgICAgICAgICB8IDQ0MyArKysrKysrKysrKysr KysrKystLQogIHNyYy9zb3J0LmMgICAgICAgICAgICAgICAgICB8IDc5MCArKysrKysrKysrKysr KysrKysrKysrKysrKysrKysrKystLS0KLSBzcmMvdW5leHBhbmQuYyAgICAgICAgICAgICAgfCAx MDEgKysrKy0KKyBzcmMvdW5leHBhbmQuYyAgICAgICAgICAgICAgfCAxMDMgKysrKy0KICB0ZXN0 cy9Db3JldXRpbHMucG0gICAgICAgICAgfCAgIDMgKwogIHRlc3RzL2V4cGFuZC9tYi5zaCAgICAg ICAgICB8IDE4MyArKysrKysrKysKICB0ZXN0cy9pMThuL3NvcnQuc2ggICAgICAgICAgfCAgMjkg KysKQEAgLTMzLDggKzMzLDggQEAgU3ViamVjdDogW1BBVENIXSBjb3JldXRpbHMtaTE4bi5wYXRj aAogIHRlc3RzL3ByL3ByLXRlc3RzLnBsICAgICAgICB8ICA0OSArKysKICB0ZXN0cy9zb3J0L3Nv cnQtbWVyZ2UucGwgICAgfCAgNDIgKysKICB0ZXN0cy9zb3J0L3NvcnQucGwgICAgICAgICAgfCAg NDAgKy0KLSB0ZXN0cy91bmV4cGFuZC9tYi5zaCAgICAgICAgfCAxNzIgKysrKysrKysKLSAzMCBm aWxlcyBjaGFuZ2VkLCAzNjMyIGluc2VydGlvbnMoKyksIDE5NSBkZWxldGlvbnMoLSkKKyB0ZXN0 cy91bmV4cGFuZC9tYi5zaCAgICAgICAgfCAxODkgKysrKysrKysrCisgMzAgZmlsZXMgY2hhbmdl ZCwgMzY0NSBpbnNlcnRpb25zKCspLCAxOTYgZGVsZXRpb25zKC0pCiAgY3JlYXRlIG1vZGUgMTAw NjQ0IGxpYi9tYmNoYXIuYwogIGNyZWF0ZSBtb2RlIDEwMDY0NCBsaWIvbWJjaGFyLmgKICBjcmVh dGUgbW9kZSAxMDA2NDQgbGliL21iZmlsZS5jCkBAIC01NDgsNyArNTQ4LDcgQEAgaW5kZXggMDAw MDAwMC4uZjRlM2U3NwogKyNpbmNsdWRlICJtYmZpbGUuaCIKIGRpZmYgLS1naXQgYS9saWIvbWJm aWxlLmggYi9saWIvbWJmaWxlLmgKIG5ldyBmaWxlIG1vZGUgMTAwNjQ0Ci1pbmRleCAwMDAwMDAw Li5jODUyZjMxCitpbmRleCAwMDAwMDAwLi45NWM3YzQyCiAtLS0gL2Rldi9udWxsCiArKysgYi9s aWIvbWJmaWxlLmgKIEBAIC0wLDAgKzEsMjc3IEBACkBAIC0xODQzLDcgKzE4NDMsNyBAQCBpbmRl eCA1ZWM3Y2U5Li42NWFjMzE1IDEwMDY0NAogIH0KICAKIGRpZmYgLS1naXQgYS9zcmMvZm9sZC5j IGIvc3JjL2ZvbGQuYwotaW5kZXggYjY0YWFkNC4uYTE1NjMzNyAxMDA2NDQKK2luZGV4IGI2NGFh ZDQuLjI0MWIxN2MgMTAwNjQ0CiAtLS0gYS9zcmMvZm9sZC5jCiArKysgYi9zcmMvZm9sZC5jCiBA QCAtMjMsMTAgKzIzLDMyIEBACkBAIC0yMjQ3LDcgKzIyNDcsNyBAQCBpbmRleCBiNjRhYWQ0Li5h MTU2MzM3IDEwMDY0NAogIAogICAgICAgICAgY2FzZSAncyc6CQkvKiBCcmVhayBhdCB3b3JkIGJv dW5kYXJpZXMuICovCiBkaWZmIC0tZ2l0IGEvc3JjL2xvY2FsLm1rIGIvc3JjL2xvY2FsLm1rCi1p bmRleCAxODhkZGExLi43ZGI1NzUzIDEwMDY0NAoraW5kZXggM2JmZTgxNC4uZTQyYmI3OSAxMDA2 NDQKIC0tLSBhL3NyYy9sb2NhbC5tawogKysrIGIvc3JjL2xvY2FsLm1rCiBAQCAtNDc4LDggKzQ3 OCw4IEBAIHNyY19iYXNlMzJfQ1BQRkxBR1MgPSAtREJBU0VfVFlQRT0zMiAkKEFNX0NQUEZMQUdT KQpAQCAtNDEwMiw3ICs0MTAyLDcgQEAgaW5kZXggN2FmMWEyNS4uZDNkYzY4NCAxMDA2NDQKICAg ICAgICAgICAgYnJlYWs7CiAgCiBkaWZmIC0tZ2l0IGEvc3JjL3VuZXhwYW5kLmMgYi9zcmMvdW5l eHBhbmQuYwotaW5kZXggZmYyMzRkNy4uN2MzNmVmNiAxMDA2NDQKK2luZGV4IGZmMjM0ZDcuLjA2 ZWE2MzcgMTAwNjQ0CiAtLS0gYS9zcmMvdW5leHBhbmQuYwogKysrIGIvc3JjL3VuZXhwYW5kLmMK IEBAIC0zOSw2ICszOSw5IEBACkBAIC00MTUyLDcgKzQxNTIsNyBAQCBpbmRleCBmZjIzNGQ3Li43 YzM2ZWY2IDEwMDY0NAogICAgICAgdGFiIHN0b3AsIHRoZW4gTUFYX0NPTFVNTl9XSURUSCAtIDEg YmxhbmtzLCB0aGVuIGEgbm9uLWJsYW5rOyBzbwogICAgICAgYWxsb2NhdGUgTUFYX0NPTFVNTl9X SURUSCBieXRlcyB0byBzdG9yZSB0aGUgYmxhbmtzLiAgKi8KIC0gIHBlbmRpbmdfYmxhbmsgPSB4 aW1hbGxvYyAobWF4X2NvbHVtbl93aWR0aCk7Ci0rICBwZW5kaW5nX2JsYW5rID0geGltYWxsb2Mg KG1heF9jb2x1bW5fd2lkdGggKiBzaXplb2YgKG1iZl9jaGFyX3QpKTsKKysgIHBlbmRpbmdfYmxh bmsgPSB4aW5tYWxsb2MgKG1heF9jb2x1bW5fd2lkdGgsIHNpemVvZiAobWJmX2NoYXJfdCkpOwog KwogKyAgaWYgKGZvdW5kX2JvbSA9PSB0cnVlKQogKyAgICBwcmludF9ib20oKTsKQEAgLTQyMTMs NyArNDIxMyw3IEBAIGluZGV4IGZmMjM0ZDcuLjdjMzZlZjYgMTAwNjQ0CiAgCiAgICAgICAgICAg ICAgICBpZiAoYmxhbmspCiAgICAgICAgICAgICAgICAgIHsKLUBAIC0xNzUsMTYgKzIzMiwxNiBA QCB1bmV4cGFuZCAodm9pZCkKK0BAIC0xNzUsMzAgKzIzMiwzMSBAQCB1bmV4cGFuZCAodm9pZCkK ICAKICAgICAgICAgICAgICAgICAgICBpZiAoY29udmVydCkKICAgICAgICAgICAgICAgICAgICAg IHsKQEAgLTQyMzEsOSArNDIzMSwxMCBAQCBpbmRleCBmZjIzNGQ3Li43YzM2ZWY2IDEwMDY0NAog LSAgICAgICAgICAgICAgICAgICAgICAgICAgY29sdW1uKys7CiArICAgICAgICAgICAgICAgICAg ICAgICAgICBjb2x1bW4gKz0gbWJfd2lkdGggKGMpOwogIAotICAgICAgICAgICAgICAgICAgICAg ICAgICAgaWYgKCEgKHByZXZfYmxhbmsgJiYgY29sdW1uID09IG5leHRfdGFiX2NvbHVtbikpCist ICAgICAgICAgICAgICAgICAgICAgICAgICBpZiAoISAocHJldl9ibGFuayAmJiBjb2x1bW4gPT0g bmV4dF90YWJfY29sdW1uKSkKKysgICAgICAgICAgICAgICAgICAgICAgICAgIGlmICghIChwcmV2 X2JsYW5rICYmIGNvbHVtbiA+PSBuZXh0X3RhYl9jb2x1bW4pKQogICAgICAgICAgICAgICAgICAg ICAgICAgICAgICB7Ci1AQCAtMTkyLDEzICsyNDksMTQgQEAgdW5leHBhbmQgKHZvaWQpCisgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgLyogSXQgaXMgbm90IHlldCBrbm93biB3aGV0aGVy IHRoZSBwZW5kaW5nIGJsYW5rcwogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHdp bGwgYmUgcmVwbGFjZWQgYnkgdGFicy4gICovCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgaWYgKGNvbHVtbiA9PSBuZXh0X3RhYl9jb2x1bW4pCiAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICBvbmVfYmxhbmtfYmVmb3JlX3RhYl9zdG9wID0gdHJ1ZTsKQEAgLTQzMjEsNyAr NDMyMiw3IEBAIGluZGV4IGI1NWZiOWQuLmFjODBmNDkgMTAwNjQ0CiAgICAgICAgICAgIHdhcm4g IiRwcm9ncmFtX25hbWU6ICR0ZXN0X25hbWU6IHRlc3QgbmFtZSBpcyB0b28gbG9uZyAoPiAkbWF4 KVxuIjsKIGRpZmYgLS1naXQgYS90ZXN0cy9leHBhbmQvbWIuc2ggYi90ZXN0cy9leHBhbmQvbWIu c2gKIG5ldyBmaWxlIG1vZGUgMTAwNjQ0Ci1pbmRleCAwMDAwMDAwLi5kZDYwMDdjCitpbmRleCAw MDAwMDAwLi42ZDY0OTdhCiAtLS0gL2Rldi9udWxsCiArKysgYi90ZXN0cy9leHBhbmQvbWIuc2gK IEBAIC0wLDAgKzEsMTgzIEBACkBAIC01MDE2LDEwICs1MDE3LDEwIEBAIGluZGV4IDJlZTkyYzQu Ljk2Yzc5NjUgMTAwNzU1CiAgbXkgJHZlcmJvc2UgPSAkRU5We1ZFUkJPU0V9OwogZGlmZiAtLWdp dCBhL3Rlc3RzL3VuZXhwYW5kL21iLnNoIGIvdGVzdHMvdW5leHBhbmQvbWIuc2gKIG5ldyBmaWxl IG1vZGUgMTAwNjQ0Ci1pbmRleCAwMDAwMDAwLi44YTgyZDc0CitpbmRleCAwMDAwMDAwLi45ZmEx ODIzCiAtLS0gL2Rldi9udWxsCiArKysgYi90ZXN0cy91bmV4cGFuZC9tYi5zaAotQEAgLTAsMCAr MSwxNzMgQEAKK0BAIC0wLDAgKzEsMTg5IEBACiArIyEvYmluL3NoCiArCiArIyBDb3B5cmlnaHQg KEMpIDIwMTItMjAxNSBGcmVlIFNvZnR3YXJlIEZvdW5kYXRpb24sIEluYy4KQEAgLTUxOTIsNyAr NTE5MywyMyBAQCBpbmRleCAwMDAwMDAwLi44YTgyZDc0CiArTENfQUxMPUMgdW5leHBhbmQgLWEg aW4gaW4gPiBvdXQgfHwgZmFpbD0xCiArY29tcGFyZSBleHAgb3V0ID4gL2Rldi9udWxsIDI+JjEg fHwgZmFpbD0xCiArCisrIyBFbnN1cmUgb3ZlcmZsb3cgaXMgaGFuZGVkIGdyYWNlZnVsbHkKKysj IGNvcmV1dGlscyB2OS4xMSBpbmR1Y2VkIGEgYnVmZmVyIG92ZXJmbG93IHdpdGggbWJfbXVsPTQg KG9yIDE2KS4KKytmb3IgbWJfbXVsIGluIDQgNjsgZG8KKysgIHByaW50ZiAnICAgXG4nIHwgdW5l eHBhbmQgLXQgJChleHByICRTSVpFX01BWCAvICRtYl9tdWwgKyAxKSAyPmVycjsgcmV0PSQ/Cisr ICB0ZXN0ICIkcmV0IiA9IDEgfHwgdGVzdCAiJHJldCIgPSAwIHx8IHsgY2F0IGVycjsgZmFpbD0x OyB9CisrZG9uZQorKworKyMgQSBibGFuayB3aG9zZSBkaXNwbGF5IHdpZHRoIGV4Y2VlZHMgdGhl IHRhYiBkaXN0YW5jZSBtdXN0IG5vdCBvdmVycnVuCisrIyB0aGUgcGVuZGluZy1ibGFuayBidWZm ZXIuICBXaXRoIC10MSBldmVyeSBjb2x1bW4gaXMgYSB0YWIgc3RvcCwgc28gYQorKyMgd2lkdGgt MiBpZGVvZ3JhcGhpYyBzcGFjZSBzdGVwcyBvdmVyIHRoZSBzdG9wIHdpdGhvdXQgbGFuZGluZyBv biBpdDsKKysjIHRoZSBydW4gb2YgYmxhbmtzIHRoZW4gZ3JldyBwZW5kaW5nX2JsYW5rIHdpdGhv dXQgYm91bmQuCisraWRlb19zcGFjZT0kKGVudiBwcmludGYgJ1x1MzAwMCcpCisreyB5ZXMgIiRp ZGVvX3NwYWNlIiB8IGhlYWQgLW4gNDAwMDAgfCB0ciAtZCAnXG4nOyBlY2hvOyB9IHwKKysgIHVu ZXhwYW5kIC10MSA+b3V0IDI+ZXJyOyByZXQ9JD8KKyt0ZXN0ICIkcmV0IiA9IDAgfHwgeyBjYXQg ZXJyOyBmYWlsPTE7IH0KKysKICtFeGl0ICRmYWlsCiAtLSAKLTIuNTAuMAorMi41NC4wCiAKCmRp ZmYgLS1naXQgYS9jb3JldXRpbHMuc3BlYyBiL2NvcmV1dGlscy5zcGVjCmluZGV4IGVmNDYxOWEu LjVjMzlmN2IgMTAwNjQ0Ci0tLSBhL2NvcmV1dGlscy5zcGVjCisrKyBiL2NvcmV1dGlscy5zcGVj CkBAIC0xLDcgKzEsNyBAQAogU3VtbWFyeTogQSBzZXQgb2YgYmFzaWMgR05VIHRvb2xzIGNvbW1v bmx5IHVzZWQgaW4gc2hlbGwgc2NyaXB0cwogTmFtZTogICAgY29yZXV0aWxzCiBWZXJzaW9uOiA5 LjcKLVJlbGVhc2U6IDglez9kaXN0fQorUmVsZWFzZTogOSV7P2Rpc3R9CiAjIHNvbWUgdXNlZCBw YXJ0cyBvZiBnbnVsaWIgYXJlIHVuZGVyIHZhcmlvdXMgdmFyaWFudHMgb2YgTEdQTAogTGljZW5z ZTogR1BMLTMuMC1vci1sYXRlciBBTkQgR0ZETC0xLjMtbm8taW52YXJpYW50cy1vci1sYXRlciBB TkQgTEdQTC0yLjEtb3ItbGF0ZXIgQU5EIExHUEwtMy4wLW9yLWxhdGVyCiBVcmw6ICAgICBodHRw czovL3d3dy5nbnUub3JnL3NvZnR3YXJlL2NvcmV1dGlscy8KQEAgLTI5OCw2ICsyOTgsOSBAQCBy bSAtZiAkUlBNX0JVSUxEX1JPT1Qle19pbmZvZGlyfS9kaXIKICVsaWNlbnNlIENPUFlJTkcKIAog JWNoYW5nZWxvZworKiBUaHUgSnVuIDExIDIwMjYgTHVrw6HFoSBaYW9yYWwgPGx6YW9yYWxAcmVk aGF0LmNvbT4gLSA5LjctOQorLSB1bmV4cGFuZDogZml4IGhlYXAgb3ZlcmZsb3dzCisKICogTW9u IE1hciAwOSAyMDI2IEx1a8OhxaEgWmFvcmFsIDxsemFvcmFsQHJlZGhhdC5jb20+IC0gOS43LTgK IC0gZml4IHVuZXhwYW5kL2V4cGFuZCBjcmFzaCBvbiBpbnZhbGlkIG11bHRpYnl0ZSBjaGFyYWN0 ZXJzIChyaGJ6IzI0NDMwNDEpCiAK