mirror of
https://github.com/FreeRTOS/FreeRTOS-Kernel.git
synced 2026-10-10 08:02:57 -04:00
Defect: pvPortMalloc() in heap_1.c can return a pointer outside the ucHeap array when configTOTAL_HEAP_SIZE is configured smaller than or equal to portBYTE_ALIGNMENT. Root cause: configADJUSTED_HEAP_SIZE is defined as ( configTOTAL_HEAP_SIZE - portBYTE_ALIGNMENT ). When configTOTAL_HEAP_SIZE is not larger than portBYTE_ALIGNMENT this unsigned subtraction underflows to a very large size_t value. The "enough room left" check in pvPortMalloc() compares an unsigned index against configADJUSTED_HEAP_SIZE, so the underflowed value defeats the check and an allocation can be handed out past the end of the heap array. Fix: add a compile-time (compiler, not preprocessor) size check so a nonsensical, too-small heap is rejected during the build. The compiler-level check still works when configTOTAL_HEAP_SIZE is defined with a cast such as ( ( size_t ) 0x2000 ). A host regression test kept outside this repository demonstrates the fault before the change and its absence afterwards (red then green). |
||
|---|---|---|
| .. | ||
| heap_1.c | ||
| heap_2.c | ||
| heap_3.c | ||
| heap_4.c | ||
| heap_5.c | ||
| ReadMe.url | ||
[{000214A0-0000-0000-C000-000000000046}]
Prop3=19,2
[InternetShortcut]
URL=https://www.FreeRTOS.org/a00111.html
IDList=