Firefox · SpiderMonkey
CVE-2025-9181
Uninitialized Memory in SpiderMonkey
Overview
Medium
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Changed Functions
| Function | Change | Notes |
|---|---|---|
ifjs/src/util/NativeStack.cpp |
modified |
Files Changed
js/src/util/NativeStack.cppmozglue/misc/StackWalk.cpp
Patch
diff --git a/js/src/util/NativeStack.cpp b/js/src/util/NativeStack.cpp
index 4e4189d3978..e77289c318a 100644
--- a/js/src/util/NativeStack.cpp
+++ b/js/src/util/NativeStack.cpp
@@ -95,17 +95,16 @@ void* js::GetNativeStackBaseImpl() {
pthread_t thread = pthread_self();
pthread_attr_t sattr;
pthread_attr_init(&sattr);
- pthread_getattr_np(thread, &sattr);
+ int rc = pthread_getattr_np(thread, &sattr);
+ MOZ_RELEASE_ASSERT(rc == 0, "pthread_getattr_np failed");
// stackBase will be the *lowest* address on all architectures.
void* stackBase = nullptr;
size_t stackSize = 0;
- int rc = pthread_attr_getstack(&sattr, &stackBase, &stackSize);
- if (rc) {
- MOZ_CRASH(
- "call to pthread_attr_getstack failed, unable to setup stack range for "
- "JS");
- }
+ rc = pthread_attr_getstack(&sattr, &stackBase, &stackSize);
+ MOZ_RELEASE_ASSERT(rc == 0,
+ "call to pthread_attr_getstack failed, unable to setup "
+ "stack range for JS");
MOZ_RELEASE_ASSERT(stackBase,
"invalid stack base, unable to setup stack range for JS");
pthread_attr_destroy(&sattr);
@@ -148,7 +147,8 @@ void* js::GetNativeStackBaseImpl() {
* FIXME: this function is non-portable;
* other POSIX systems may have different np alternatives
*/
- pthread_getattr_np(thread, &sattr);
+ MOZ_RELEASE_ASSERT(pthread_getattr_np(thread, &sattr) == 0,
+ "pthread_getattr_np failed");
# endif
void* stackBase = 0;
diff --git a/mozglue/misc/StackWalk.cpp b/mozglue/misc/StackWalk.cpp
index 7216a62fe9c..cc62b4d7859 100644
--- a/mozglue/misc/StackWalk.cpp
+++ b/mozglue/misc/StackWalk.cpp
@@ -949,7 +949,8 @@ MFBT_API void MozStackWalk(MozWalkStackCallback aCallback,
# elif defined(ANDROID)
pthread_attr_t sattr;
pthread_attr_init(&sattr);
- pthread_getattr_np(pthread_self(), &sattr);
+ int rc = pthread_getattr_np(pthread_self(), &sattr);
+ MOZ_RELEASE_ASSERT(rc == 0, "pthread_getattr_np failed");
void* stackBase = stackEnd = nullptr;
size_t stackSize = 0;
if (gettid() != getpid()) {
Loading diff…
References
On This Page