dcavalca / rpms / grub2

Forked from rpms/grub2 3 years ago
Clone

Blame SOURCES/0302-calloc-Use-calloc-at-most-places.patch

b1bcb2
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
c4e390
From: Peter Jones <pjones@redhat.com>
c4e390
Date: Mon, 15 Jun 2020 12:26:01 -0400
b1bcb2
Subject: [PATCH] calloc: Use calloc() at most places
c4e390
c4e390
This modifies most of the places we do some form of:
c4e390
c4e390
  X = malloc(Y * Z);
c4e390
c4e390
to use calloc(Y, Z) instead.
c4e390
c4e390
Among other issues, this fixes:
c4e390
  - allocation of integer overflow in grub_png_decode_image_header()
c4e390
    reported by Chris Coulson,
c4e390
  - allocation of integer overflow in luks_recover_key()
c4e390
    reported by Chris Coulson,
c4e390
  - allocation of integer overflow in grub_lvm_detect()
c4e390
    reported by Chris Coulson.
c4e390
c4e390
Fixes: CVE-2020-14308
c4e390
c4e390
Signed-off-by: Peter Jones <pjones@redhat.com>
c4e390
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
c4e390
Upstream-commit-id: 48eeedf1e4b
c4e390
---
b1bcb2
 grub-core/bus/usb/usbhub.c                |  8 ++--
c4e390
 grub-core/commands/efi/lsefisystab.c      |  3 +-
b1bcb2
 grub-core/commands/legacycfg.c            | 25 ++++++++++--
c4e390
 grub-core/commands/menuentry.c            |  2 +-
c4e390
 grub-core/commands/nativedisk.c           |  2 +-
b1bcb2
 grub-core/commands/parttool.c             | 12 ++++--
c4e390
 grub-core/commands/regexp.c               |  2 +-
c4e390
 grub-core/commands/search_wrap.c          |  2 +-
c4e390
 grub-core/disk/diskfilter.c               |  4 +-
b1bcb2
 grub-core/disk/ldm.c                      | 14 +++----
c4e390
 grub-core/disk/luks.c                     |  2 +-
b1bcb2
 grub-core/disk/lvm.c                      |  8 ++--
c4e390
 grub-core/disk/xen/xendisk.c              |  2 +-
c4e390
 grub-core/efiemu/loadcore.c               |  2 +-
c4e390
 grub-core/efiemu/mm.c                     |  6 +--
c4e390
 grub-core/font/font.c                     |  3 +-
c4e390
 grub-core/fs/affs.c                       |  6 +--
c4e390
 grub-core/fs/btrfs.c                      |  4 +-
c4e390
 grub-core/fs/hfs.c                        |  2 +-
b1bcb2
 grub-core/fs/hfsplus.c                    | 63 +++++++++++++++++++++----------
c4e390
 grub-core/fs/iso9660.c                    |  2 +-
c4e390
 grub-core/fs/ntfs.c                       |  4 +-
c4e390
 grub-core/fs/sfs.c                        |  2 +-
c4e390
 grub-core/fs/tar.c                        |  2 +-
c4e390
 grub-core/fs/udf.c                        |  4 +-
c4e390
 grub-core/fs/zfs/zfs.c                    |  4 +-
c4e390
 grub-core/gfxmenu/gui_string_util.c       |  2 +-
c4e390
 grub-core/gfxmenu/widget-box.c            |  4 +-
c4e390
 grub-core/io/gzio.c                       |  2 +-
b1bcb2
 grub-core/kern/efi/efi.c                  | 31 ++++++++++++---
c4e390
 grub-core/kern/emu/hostdisk.c             |  2 +-
c4e390
 grub-core/kern/fs.c                       |  2 +-
c4e390
 grub-core/kern/misc.c                     |  2 +-
c4e390
 grub-core/kern/parser.c                   |  2 +-
c4e390
 grub-core/kern/uboot/uboot.c              |  2 +-
b1bcb2
 grub-core/lib/libgcrypt/cipher/ac.c       |  8 ++--
c4e390
 grub-core/lib/libgcrypt/cipher/primegen.c |  4 +-
c4e390
 grub-core/lib/libgcrypt/cipher/pubkey.c   |  4 +-
c4e390
 grub-core/lib/priority_queue.c            |  2 +-
b1bcb2
 grub-core/lib/reed_solomon.c              |  7 ++--
b1bcb2
 grub-core/lib/relocator.c                 | 10 ++---
c4e390
 grub-core/loader/arm/linux.c              |  2 +-
b1bcb2
 grub-core/loader/efi/chainloader.c        | 11 ++++--
c4e390
 grub-core/loader/i386/bsdXX.c             |  2 +-
c4e390
 grub-core/loader/i386/xnu.c               |  4 +-
c4e390
 grub-core/loader/macho.c                  |  2 +-
c4e390
 grub-core/loader/multiboot_elfxx.c        |  2 +-
c4e390
 grub-core/loader/xnu.c                    |  2 +-
c4e390
 grub-core/mmap/mmap.c                     |  4 +-
c4e390
 grub-core/net/bootp.c                     |  2 +-
b1bcb2
 grub-core/net/dns.c                       | 10 ++---
c4e390
 grub-core/net/net.c                       |  4 +-
b1bcb2
 grub-core/normal/charset.c                | 10 ++---
b1bcb2
 grub-core/normal/cmdline.c                | 14 +++----
b1bcb2
 grub-core/normal/menu_entry.c             | 14 +++----
c4e390
 grub-core/normal/menu_text.c              |  4 +-
c4e390
 grub-core/normal/term.c                   |  4 +-
c4e390
 grub-core/osdep/linux/getroot.c           |  6 +--
c4e390
 grub-core/osdep/unix/config.c             |  2 +-
c4e390
 grub-core/osdep/windows/getroot.c         |  2 +-
c4e390
 grub-core/osdep/windows/hostdisk.c        |  4 +-
c4e390
 grub-core/osdep/windows/init.c            |  2 +-
c4e390
 grub-core/osdep/windows/platform.c        |  4 +-
c4e390
 grub-core/osdep/windows/relpath.c         |  2 +-
c4e390
 grub-core/partmap/gpt.c                   |  2 +-
c4e390
 grub-core/partmap/msdos.c                 |  2 +-
c4e390
 grub-core/script/execute.c                |  2 +-
c4e390
 grub-core/tests/fake_input.c              |  2 +-
c4e390
 grub-core/tests/video_checksum.c          |  6 +--
c4e390
 grub-core/video/capture.c                 |  2 +-
c4e390
 grub-core/video/emu/sdl.c                 |  2 +-
c4e390
 grub-core/video/i386/pc/vga.c             |  2 +-
c4e390
 grub-core/video/readers/png.c             |  2 +-
c4e390
 util/getroot.c                            |  2 +-
c4e390
 util/grub-file.c                          |  2 +-
c4e390
 util/grub-fstest.c                        |  2 +-
c4e390
 util/grub-install-common.c                |  2 +-
c4e390
 util/grub-install.c                       |  4 +-
c4e390
 util/grub-mkimagexx.c                     |  4 +-
c4e390
 util/grub-mkstandalone.c                  |  2 +-
b1bcb2
 util/grub-pe2elf.c                        | 12 +++---
c4e390
 util/grub-probe.c                         |  4 +-
c4e390
 include/grub/unicode.h                    |  4 +-
c4e390
 83 files changed, 261 insertions(+), 186 deletions(-)
c4e390
c4e390
diff --git a/grub-core/bus/usb/usbhub.c b/grub-core/bus/usb/usbhub.c
c4e390
index 34a7ff1b5f8..a06cce302d2 100644
c4e390
--- a/grub-core/bus/usb/usbhub.c
c4e390
+++ b/grub-core/bus/usb/usbhub.c
c4e390
@@ -149,8 +149,8 @@ grub_usb_add_hub (grub_usb_device_t dev)
c4e390
   grub_usb_set_configuration (dev, 1);
c4e390
 
c4e390
   dev->nports = hubdesc.portcnt;
c4e390
-  dev->children = grub_zalloc (hubdesc.portcnt * sizeof (dev->children[0]));
c4e390
-  dev->ports = grub_zalloc (dev->nports * sizeof (dev->ports[0]));
c4e390
+  dev->children = grub_calloc (hubdesc.portcnt, sizeof (dev->children[0]));
c4e390
+  dev->ports = grub_calloc (dev->nports, sizeof (dev->ports[0]));
c4e390
   if (!dev->children || !dev->ports)
c4e390
     {
c4e390
       grub_free (dev->children);
c4e390
@@ -268,8 +268,8 @@ grub_usb_controller_dev_register_iter (grub_usb_controller_t controller, void *d
c4e390
 
c4e390
   /* Query the number of ports the root Hub has.  */
c4e390
   hub->nports = controller->dev->hubports (controller);
c4e390
-  hub->devices = grub_zalloc (sizeof (hub->devices[0]) * hub->nports);
c4e390
-  hub->ports = grub_zalloc (sizeof (hub->ports[0]) * hub->nports);
c4e390
+  hub->devices = grub_calloc (hub->nports, sizeof (hub->devices[0]));
c4e390
+  hub->ports = grub_calloc (hub->nports, sizeof (hub->ports[0]));
c4e390
   if (!hub->devices || !hub->ports)
c4e390
     {
c4e390
       grub_free (hub->devices);
c4e390
diff --git a/grub-core/commands/efi/lsefisystab.c b/grub-core/commands/efi/lsefisystab.c
c4e390
index 8717db91ea2..2a86bd53aeb 100644
c4e390
--- a/grub-core/commands/efi/lsefisystab.c
c4e390
+++ b/grub-core/commands/efi/lsefisystab.c
c4e390
@@ -61,7 +61,8 @@ grub_cmd_lsefisystab (struct grub_command *cmd __attribute__ ((unused)),
c4e390
     grub_printf ("Vendor: ");
c4e390
     
c4e390
     for (vendor_utf16 = st->firmware_vendor; *vendor_utf16; vendor_utf16++);
c4e390
-    vendor = grub_malloc (4 * (vendor_utf16 - st->firmware_vendor) + 1);
c4e390
+    /* Allocate extra 3 bytes to simplify math. */
c4e390
+    vendor = grub_calloc (4, vendor_utf16 - st->firmware_vendor + 1);
c4e390
     if (!vendor)
c4e390
       return grub_errno;
c4e390
     *grub_utf16_to_utf8 ((grub_uint8_t *) vendor, st->firmware_vendor,
c4e390
diff --git a/grub-core/commands/legacycfg.c b/grub-core/commands/legacycfg.c
c4e390
index 2c09fb7dd78..d1127fa8968 100644
c4e390
--- a/grub-core/commands/legacycfg.c
c4e390
+++ b/grub-core/commands/legacycfg.c
c4e390
@@ -244,6 +244,7 @@ grub_cmd_legacy_kernel (struct grub_command *mycmd __attribute__ ((unused)),
c4e390
   struct grub_command *cmd;
c4e390
   char **cutargs;
c4e390
   int cutargc;
c4e390
+  grub_err_t err = 0;
c4e390
   
c4e390
   for (i = 0; i < 2; i++)
c4e390
     {
c4e390
@@ -304,7 +305,14 @@ grub_cmd_legacy_kernel (struct grub_command *mycmd __attribute__ ((unused)),
c4e390
   if (argc < 2)
c4e390
     return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("filename expected"));
c4e390
 
c4e390
-  cutargs = grub_malloc (sizeof (cutargs[0]) * (argc - 1));
c4e390
+  cutargs = grub_calloc (argc - 1, sizeof (cutargs[0]));
c4e390
+  err = grub_errno;
c4e390
+  if (!cutargs)
c4e390
+    {
c4e390
+out:
c4e390
+      grub_errno = err;
c4e390
+      return grub_errno;
c4e390
+    }
c4e390
   cutargc = argc - 1;
c4e390
   grub_memcpy (cutargs + 1, args + 2, sizeof (cutargs[0]) * (argc - 2));
c4e390
   cutargs[0] = args[0];
c4e390
@@ -420,7 +428,12 @@ grub_cmd_legacy_kernel (struct grub_command *mycmd __attribute__ ((unused)),
c4e390
 	    {
c4e390
 	      char rbuf[3] = "-r";
c4e390
 	      bsdargc = cutargc + 2;
c4e390
-	      bsdargs = grub_malloc (sizeof (bsdargs[0]) * bsdargc);
c4e390
+	      bsdargs = grub_calloc (bsdargc, sizeof (bsdargs[0]));
c4e390
+	      if (!bsdargs)
c4e390
+		{
c4e390
+		  err = grub_errno;
c4e390
+		  goto out;
c4e390
+		}
c4e390
 	      grub_memcpy (bsdargs, args, argc * sizeof (bsdargs[0]));
c4e390
 	      bsdargs[argc] = rbuf;
c4e390
 	      bsdargs[argc + 1] = bsddevname;
c4e390
@@ -523,7 +536,13 @@ grub_cmd_legacy_initrdnounzip (struct grub_command *mycmd __attribute__ ((unused
c4e390
       char **newargs;
c4e390
       grub_err_t err;
c4e390
       char nounzipbuf[10] = "--nounzip";
c4e390
-      newargs = grub_malloc ((argc + 1) * sizeof (newargs[0]));
c4e390
+
c4e390
+      cmd = grub_command_find ("module");
c4e390
+      if (!cmd)
c4e390
+	return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("can't find command `%s'"),
c4e390
+			   "module");
c4e390
+
c4e390
+      newargs = grub_calloc (argc + 1, sizeof (newargs[0]));
c4e390
       if (!newargs)
c4e390
 	return grub_errno;
c4e390
       grub_memcpy (newargs + 1, args, argc * sizeof (newargs[0]));
c4e390
diff --git a/grub-core/commands/menuentry.c b/grub-core/commands/menuentry.c
c4e390
index 58d4dadf6ee..16c52ed00e8 100644
c4e390
--- a/grub-core/commands/menuentry.c
c4e390
+++ b/grub-core/commands/menuentry.c
c4e390
@@ -154,7 +154,7 @@ grub_normal_add_menu_entry (int argc, const char **args,
c4e390
     goto fail;
c4e390
 
c4e390
   /* Save argc, args to pass as parameters to block arg later. */
c4e390
-  menu_args = grub_malloc (sizeof (char*) * (argc + 1));
c4e390
+  menu_args = grub_calloc (argc + 1, sizeof (char *));
c4e390
   if (! menu_args)
c4e390
     goto fail;
c4e390
 
c4e390
diff --git a/grub-core/commands/nativedisk.c b/grub-core/commands/nativedisk.c
c4e390
index 33b6b99eaaf..36298cf2ed4 100644
c4e390
--- a/grub-core/commands/nativedisk.c
c4e390
+++ b/grub-core/commands/nativedisk.c
c4e390
@@ -191,7 +191,7 @@ grub_cmd_nativedisk (grub_command_t cmd __attribute__ ((unused)),
c4e390
   else
c4e390
     path_prefix = prefix;
c4e390
 
c4e390
-  mods = grub_malloc (argc * sizeof (mods[0]));
c4e390
+  mods = grub_calloc (argc, sizeof (mods[0]));
c4e390
   if (!mods)
c4e390
     return grub_errno;
c4e390
 
c4e390
diff --git a/grub-core/commands/parttool.c b/grub-core/commands/parttool.c
c4e390
index a47ff0776c1..a79b84a565b 100644
c4e390
--- a/grub-core/commands/parttool.c
c4e390
+++ b/grub-core/commands/parttool.c
c4e390
@@ -59,7 +59,13 @@ grub_parttool_register(const char *part_name,
c4e390
   for (nargs = 0; args[nargs].name != 0; nargs++);
c4e390
   cur->nargs = nargs;
c4e390
   cur->args = (struct grub_parttool_argdesc *)
c4e390
-    grub_malloc ((nargs + 1) * sizeof (struct grub_parttool_argdesc));
c4e390
+    grub_calloc (nargs + 1, sizeof (struct grub_parttool_argdesc));
c4e390
+  if (!cur->args)
c4e390
+    {
c4e390
+      grub_free (cur);
c4e390
+      curhandle--;
c4e390
+      return -1;
c4e390
+    }
c4e390
   grub_memcpy (cur->args, args,
c4e390
 	       (nargs + 1) * sizeof (struct grub_parttool_argdesc));
c4e390
 
c4e390
@@ -249,7 +255,7 @@ grub_cmd_parttool (grub_command_t cmd __attribute__ ((unused)),
c4e390
     if (grub_strcmp (args[i], "help") == 0)
c4e390
       return show_help (dev);
c4e390
 
c4e390
-  parsed = (int *) grub_zalloc (argc * sizeof (int));
c4e390
+  parsed = (int *) grub_calloc (argc, sizeof (int));
c4e390
 
c4e390
   for (i = 1; i < argc; i++)
c4e390
     if (! parsed[i])
c4e390
@@ -278,7 +284,7 @@ grub_cmd_parttool (grub_command_t cmd __attribute__ ((unused)),
c4e390
 			     args[i]);
c4e390
 	ptool = cur;
c4e390
 	pargs = (struct grub_parttool_args *)
c4e390
-	  grub_zalloc (ptool->nargs * sizeof (struct grub_parttool_args));
c4e390
+	  grub_calloc (ptool->nargs, sizeof (struct grub_parttool_args));
c4e390
 	for (j = i; j < argc; j++)
c4e390
 	  if (! parsed[j])
c4e390
 	    {
c4e390
diff --git a/grub-core/commands/regexp.c b/grub-core/commands/regexp.c
c4e390
index f00b184c81e..4019164f365 100644
c4e390
--- a/grub-core/commands/regexp.c
c4e390
+++ b/grub-core/commands/regexp.c
c4e390
@@ -116,7 +116,7 @@ grub_cmd_regexp (grub_extcmd_context_t ctxt, int argc, char **args)
c4e390
   if (ret)
c4e390
     goto fail;
c4e390
 
c4e390
-  matches = grub_zalloc (sizeof (*matches) * (regex.re_nsub + 1));
c4e390
+  matches = grub_calloc (regex.re_nsub + 1, sizeof (*matches));
c4e390
   if (! matches)
c4e390
     goto fail;
c4e390
 
c4e390
diff --git a/grub-core/commands/search_wrap.c b/grub-core/commands/search_wrap.c
c4e390
index 3f75fecdf1d..07ba57072df 100644
c4e390
--- a/grub-core/commands/search_wrap.c
c4e390
+++ b/grub-core/commands/search_wrap.c
c4e390
@@ -122,7 +122,7 @@ grub_cmd_search (grub_extcmd_context_t ctxt, int argc, char **args)
c4e390
     for (i = 0; state[SEARCH_HINT_BAREMETAL].args[i]; i++)
c4e390
       nhints++;
c4e390
 
c4e390
-  hints = grub_malloc (sizeof (hints[0]) * nhints);
c4e390
+  hints = grub_calloc (nhints, sizeof (hints[0]));
c4e390
   if (!hints)
c4e390
     return grub_errno;
c4e390
   j = 0;
c4e390
diff --git a/grub-core/disk/diskfilter.c b/grub-core/disk/diskfilter.c
c4e390
index e8a3bcbd138..509c0f353c7 100644
c4e390
--- a/grub-core/disk/diskfilter.c
c4e390
+++ b/grub-core/disk/diskfilter.c
c4e390
@@ -1013,7 +1013,7 @@ grub_diskfilter_make_raid (grub_size_t uuidlen, char *uuid, int nmemb,
c4e390
   array->lvs->segments->node_count = nmemb;
c4e390
   array->lvs->segments->raid_member_size = disk_size;
c4e390
   array->lvs->segments->nodes
c4e390
-    = grub_zalloc (nmemb * sizeof (array->lvs->segments->nodes[0]));
c4e390
+    = grub_calloc (nmemb, sizeof (array->lvs->segments->nodes[0]));
c4e390
   array->lvs->segments->stripe_size = stripe_size;
c4e390
   for (i = 0; i < nmemb; i++)
c4e390
     {
c4e390
@@ -1092,7 +1092,7 @@ insert_array (grub_disk_t disk, const struct grub_diskfilter_pv_id *id,
c4e390
 	  grub_partition_t p;
c4e390
 	  for (p = disk->partition; p; p = p->parent)
c4e390
 	    s++;
c4e390
-	  pv->partmaps = xmalloc (s * sizeof (pv->partmaps[0]));
c4e390
+	  pv->partmaps = xcalloc (s, sizeof (pv->partmaps[0]));
c4e390
 	  s = 0;
c4e390
 	  for (p = disk->partition; p; p = p->parent)
c4e390
 	    pv->partmaps[s++] = xstrdup (p->partmap->name);
c4e390
diff --git a/grub-core/disk/ldm.c b/grub-core/disk/ldm.c
c4e390
index 8075f2a9eee..97a482705d0 100644
c4e390
--- a/grub-core/disk/ldm.c
c4e390
+++ b/grub-core/disk/ldm.c
c4e390
@@ -323,8 +323,8 @@ make_vg (grub_disk_t disk,
c4e390
 	  lv->segments->type = GRUB_DISKFILTER_MIRROR;
c4e390
 	  lv->segments->node_count = 0;
c4e390
 	  lv->segments->node_alloc = 8;
c4e390
-	  lv->segments->nodes = grub_zalloc (sizeof (*lv->segments->nodes)
c4e390
-					     * lv->segments->node_alloc);
c4e390
+	  lv->segments->nodes = grub_calloc (lv->segments->node_alloc,
c4e390
+					     sizeof (*lv->segments->nodes));
c4e390
 	  if (!lv->segments->nodes)
c4e390
 	    goto fail2;
c4e390
 	  ptr = vblk[i].dynamic;
c4e390
@@ -543,8 +543,8 @@ make_vg (grub_disk_t disk,
c4e390
 	    {
c4e390
 	      comp->segment_alloc = 8;
c4e390
 	      comp->segment_count = 0;
c4e390
-	      comp->segments = grub_malloc (sizeof (*comp->segments)
c4e390
-					    * comp->segment_alloc);
c4e390
+	      comp->segments = grub_calloc (comp->segment_alloc,
c4e390
+					    sizeof (*comp->segments));
c4e390
 	      if (!comp->segments)
c4e390
 		goto fail2;
c4e390
 	    }
c4e390
@@ -590,8 +590,8 @@ make_vg (grub_disk_t disk,
c4e390
 		}
c4e390
 	      comp->segments->node_count = read_int (ptr + 1, *ptr);
c4e390
 	      comp->segments->node_alloc = comp->segments->node_count;
c4e390
-	      comp->segments->nodes = grub_zalloc (sizeof (*comp->segments->nodes)
c4e390
-						   * comp->segments->node_alloc);
c4e390
+	      comp->segments->nodes = grub_calloc (comp->segments->node_alloc,
c4e390
+						   sizeof (*comp->segments->nodes));
c4e390
 	      if (!lv->segments->nodes)
c4e390
 		goto fail2;
c4e390
 	    }
c4e390
@@ -1017,7 +1017,7 @@ grub_util_ldm_embed (struct grub_disk *disk, unsigned int *nsectors,
c4e390
       *nsectors = lv->size;
c4e390
       if (*nsectors > max_nsectors)
c4e390
 	*nsectors = max_nsectors;
c4e390
-      *sectors = grub_malloc (*nsectors * sizeof (**sectors));
c4e390
+      *sectors = grub_calloc (*nsectors, sizeof (**sectors));
c4e390
       if (!*sectors)
c4e390
 	return grub_errno;
c4e390
       for (i = 0; i < *nsectors; i++)
c4e390
diff --git a/grub-core/disk/luks.c b/grub-core/disk/luks.c
c4e390
index 25020294712..7e682b5207a 100644
c4e390
--- a/grub-core/disk/luks.c
c4e390
+++ b/grub-core/disk/luks.c
c4e390
@@ -324,7 +324,7 @@ luks_recover_key (grub_disk_t source,
c4e390
 	&& grub_be_to_cpu32 (header.keyblock[i].stripes) > max_stripes)
c4e390
       max_stripes = grub_be_to_cpu32 (header.keyblock[i].stripes);
c4e390
 
c4e390
-  split_key = grub_malloc (keysize * max_stripes);
c4e390
+  split_key = grub_calloc (keysize, max_stripes);
c4e390
   if (!split_key)
c4e390
     return grub_errno;
c4e390
 
c4e390
diff --git a/grub-core/disk/lvm.c b/grub-core/disk/lvm.c
c4e390
index 862a9664f2c..680a796cb48 100644
c4e390
--- a/grub-core/disk/lvm.c
c4e390
+++ b/grub-core/disk/lvm.c
c4e390
@@ -173,7 +173,7 @@ grub_lvm_detect (grub_disk_t disk,
c4e390
      first one.  */
c4e390
 
c4e390
   /* Allocate buffer space for the circular worst-case scenario. */
c4e390
-  metadatabuf = grub_malloc (2 * mda_size);
c4e390
+  metadatabuf = grub_calloc (2, mda_size);
c4e390
   if (! metadatabuf)
c4e390
     goto fail;
c4e390
 
c4e390
@@ -426,7 +426,7 @@ grub_lvm_detect (grub_disk_t disk,
c4e390
 #endif
c4e390
 		  goto lvs_fail;
c4e390
 		}
c4e390
-	      lv->segments = grub_malloc (sizeof (*seg) * lv->segment_count);
c4e390
+	      lv->segments = grub_calloc (lv->segment_count, sizeof (*seg));
c4e390
 	      seg = lv->segments;
c4e390
 
c4e390
 	      for (i = 0; i < lv->segment_count; i++)
c4e390
@@ -483,8 +483,8 @@ grub_lvm_detect (grub_disk_t disk,
c4e390
 		      if (seg->node_count != 1)
c4e390
 			seg->stripe_size = grub_lvm_getvalue (&p, "stripe_size = ");
c4e390
 
c4e390
-		      seg->nodes = grub_zalloc (sizeof (*stripe)
c4e390
-						* seg->node_count);
c4e390
+		      seg->nodes = grub_calloc (seg->node_count,
c4e390
+						sizeof (*stripe));
c4e390
 		      stripe = seg->nodes;
c4e390
 
c4e390
 		      p = grub_strstr (p, "stripes = [");
c4e390
diff --git a/grub-core/disk/xen/xendisk.c b/grub-core/disk/xen/xendisk.c
c4e390
index 2b11c2a2eaa..0c6778b0eed 100644
c4e390
--- a/grub-core/disk/xen/xendisk.c
c4e390
+++ b/grub-core/disk/xen/xendisk.c
c4e390
@@ -399,7 +399,7 @@ grub_xendisk_init (void)
c4e390
   if (!ctr)
c4e390
     return;
c4e390
 
c4e390
-  virtdisks = grub_malloc (ctr * sizeof (virtdisks[0]));
c4e390
+  virtdisks = grub_calloc (ctr, sizeof (virtdisks[0]));
c4e390
   if (!virtdisks)
c4e390
     return;
c4e390
   if (grub_xenstore_dir ("device/vbd", fill, &ctr))
c4e390
diff --git a/grub-core/efiemu/loadcore.c b/grub-core/efiemu/loadcore.c
c4e390
index 6968b3719ca..d6b30f6e99d 100644
c4e390
--- a/grub-core/efiemu/loadcore.c
c4e390
+++ b/grub-core/efiemu/loadcore.c
c4e390
@@ -198,7 +198,7 @@ grub_efiemu_count_symbols (const Elf_Ehdr *e)
c4e390
 
c4e390
   grub_efiemu_nelfsyms = (unsigned) s->sh_size / (unsigned) s->sh_entsize;
c4e390
   grub_efiemu_elfsyms = (struct grub_efiemu_elf_sym *)
c4e390
-    grub_malloc (sizeof (struct grub_efiemu_elf_sym) * grub_efiemu_nelfsyms);
c4e390
+    grub_calloc (grub_efiemu_nelfsyms, sizeof (struct grub_efiemu_elf_sym));
c4e390
 
c4e390
   /* Relocators */
c4e390
   for (i = 0, s = (Elf_Shdr *) ((char *) e + e->e_shoff);
c4e390
diff --git a/grub-core/efiemu/mm.c b/grub-core/efiemu/mm.c
c4e390
index e606dbffc92..3a7cd28e98f 100644
c4e390
--- a/grub-core/efiemu/mm.c
c4e390
+++ b/grub-core/efiemu/mm.c
c4e390
@@ -553,11 +553,11 @@ grub_efiemu_mmap_sort_and_uniq (void)
c4e390
   /* Initialize variables*/
c4e390
   grub_memset (present, 0, sizeof (int) * GRUB_EFI_MAX_MEMORY_TYPE);
c4e390
   scanline_events = (struct grub_efiemu_mmap_scan *)
c4e390
-    grub_malloc (sizeof (struct grub_efiemu_mmap_scan) * 2 * mmap_num);
c4e390
+    grub_calloc (mmap_num, sizeof (struct grub_efiemu_mmap_scan) * 2);
c4e390
 
c4e390
   /* Number of chunks can't increase more than by factor of 2 */
c4e390
   result = (grub_efi_memory_descriptor_t *)
c4e390
-    grub_malloc (sizeof (grub_efi_memory_descriptor_t) * 2 * mmap_num);
c4e390
+    grub_calloc (mmap_num, sizeof (grub_efi_memory_descriptor_t) * 2);
c4e390
   if (!result || !scanline_events)
c4e390
     {
c4e390
       grub_free (result);
c4e390
@@ -659,7 +659,7 @@ grub_efiemu_mm_do_alloc (void)
c4e390
 
c4e390
   /* Preallocate mmap */
c4e390
   efiemu_mmap = (grub_efi_memory_descriptor_t *)
c4e390
-    grub_malloc (mmap_reserved_size * sizeof (grub_efi_memory_descriptor_t));
c4e390
+    grub_calloc (mmap_reserved_size, sizeof (grub_efi_memory_descriptor_t));
c4e390
   if (!efiemu_mmap)
c4e390
     {
c4e390
       grub_efiemu_unload ();
c4e390
diff --git a/grub-core/font/font.c b/grub-core/font/font.c
c4e390
index 14b93e17251..b5f43d992a4 100644
c4e390
--- a/grub-core/font/font.c
c4e390
+++ b/grub-core/font/font.c
c4e390
@@ -293,8 +293,7 @@ load_font_index (grub_file_t file, grub_uint32_t sect_length, struct
c4e390
   font->num_chars = sect_length / FONT_CHAR_INDEX_ENTRY_SIZE;
c4e390
 
c4e390
   /* Allocate the character index array.  */
c4e390
-  font->char_index = grub_malloc (font->num_chars
c4e390
-				  * sizeof (struct char_index_entry));
c4e390
+  font->char_index = grub_calloc (font->num_chars, sizeof (struct char_index_entry));
c4e390
   if (!font->char_index)
c4e390
     return 1;
c4e390
   font->bmp_idx = grub_malloc (0x10000 * sizeof (grub_uint16_t));
c4e390
diff --git a/grub-core/fs/affs.c b/grub-core/fs/affs.c
c4e390
index f673897e0fd..91073795f90 100644
c4e390
--- a/grub-core/fs/affs.c
c4e390
+++ b/grub-core/fs/affs.c
c4e390
@@ -301,7 +301,7 @@ grub_affs_read_symlink (grub_fshelp_node_t node)
c4e390
       return 0;
c4e390
     }
c4e390
   latin1[symlink_size] = 0;
c4e390
-  utf8 = grub_malloc (symlink_size * GRUB_MAX_UTF8_PER_LATIN1 + 1);
c4e390
+  utf8 = grub_calloc (GRUB_MAX_UTF8_PER_LATIN1 + 1, symlink_size);
c4e390
   if (!utf8)
c4e390
     {
c4e390
       grub_free (latin1);
c4e390
@@ -422,7 +422,7 @@ grub_affs_iterate_dir (grub_fshelp_node_t dir,
c4e390
 	return 1;
c4e390
     }
c4e390
 
c4e390
-  hashtable = grub_zalloc (data->htsize * sizeof (*hashtable));
c4e390
+  hashtable = grub_calloc (data->htsize, sizeof (*hashtable));
c4e390
   if (!hashtable)
c4e390
     return 1;
c4e390
 
c4e390
@@ -628,7 +628,7 @@ grub_affs_label (grub_device_t device, char **label)
c4e390
       len = file.namelen;
c4e390
       if (len > sizeof (file.name))
c4e390
 	len = sizeof (file.name);
c4e390
-      *label = grub_malloc (len * GRUB_MAX_UTF8_PER_LATIN1 + 1);
c4e390
+      *label = grub_calloc (GRUB_MAX_UTF8_PER_LATIN1 + 1, len);
c4e390
       if (*label)
c4e390
 	*grub_latin1_to_utf8 ((grub_uint8_t *) *label, file.name, len) = '\0';
c4e390
     }
c4e390
diff --git a/grub-core/fs/btrfs.c b/grub-core/fs/btrfs.c
c4e390
index 24a71045025..db57875f490 100644
c4e390
--- a/grub-core/fs/btrfs.c
c4e390
+++ b/grub-core/fs/btrfs.c
c4e390
@@ -375,7 +375,7 @@ lower_bound (struct grub_btrfs_data *data,
c4e390
     {
c4e390
       desc->allocated = 16;
c4e390
       desc->depth = 0;
c4e390
-      desc->data = grub_malloc (sizeof (desc->data[0]) * desc->allocated);
c4e390
+      desc->data = grub_calloc (desc->allocated, sizeof (desc->data[0]));
c4e390
       if (!desc->data)
c4e390
 	return grub_errno;
c4e390
     }
c4e390
@@ -1732,7 +1732,7 @@ grub_btrfs_embed (grub_device_t device __attribute__ ((unused)),
c4e390
   *nsectors = 64 * 2 - 1;
c4e390
   if (*nsectors > max_nsectors)
c4e390
     *nsectors = max_nsectors;
c4e390
-  *sectors = grub_malloc (*nsectors * sizeof (**sectors));
c4e390
+  *sectors = grub_calloc (*nsectors, sizeof (**sectors));
c4e390
   if (!*sectors)
c4e390
     return grub_errno;
c4e390
   for (i = 0; i < *nsectors; i++)
c4e390
diff --git a/grub-core/fs/hfs.c b/grub-core/fs/hfs.c
c4e390
index d1dc015455d..79f6845879a 100644
c4e390
--- a/grub-core/fs/hfs.c
c4e390
+++ b/grub-core/fs/hfs.c
c4e390
@@ -1360,7 +1360,7 @@ grub_hfs_label (grub_device_t device, char **label)
c4e390
       grub_size_t len = data->sblock.volname[0];
c4e390
       if (len > sizeof (data->sblock.volname) - 1)
c4e390
 	len = sizeof (data->sblock.volname) - 1;
c4e390
-      *label = grub_malloc (len * MAX_UTF8_PER_MAC_ROMAN + 1);
c4e390
+      *label = grub_calloc (MAX_UTF8_PER_MAC_ROMAN + 1, len);
c4e390
       if (*label)
c4e390
 	macroman_to_utf8 (*label, data->sblock.volname + 1,
c4e390
 			  len + 1, 0);
c4e390
diff --git a/grub-core/fs/hfsplus.c b/grub-core/fs/hfsplus.c
c4e390
index 950d8a1e1c6..05016ee98a4 100644
c4e390
--- a/grub-core/fs/hfsplus.c
c4e390
+++ b/grub-core/fs/hfsplus.c
c4e390
@@ -655,6 +655,7 @@ list_nodes (void *record, void *hook_arg)
c4e390
   char *filename;
c4e390
   int i;
c4e390
   struct grub_fshelp_node *node;
c4e390
+  grub_uint16_t *keyname;
c4e390
   struct grub_hfsplus_catfile *fileinfo;
c4e390
   enum grub_fshelp_filetype type = GRUB_FSHELP_UNKNOWN;
c4e390
   struct list_nodes_ctx *ctx = hook_arg;
c4e390
@@ -713,29 +714,33 @@ list_nodes (void *record, void *hook_arg)
c4e390
   if (! filename)
c4e390
     return 0;
c4e390
 
c4e390
+  keyname = grub_calloc (grub_be_to_cpu16 (catkey->namelen), sizeof (*keyname));
c4e390
+  if (!keyname)
c4e390
+    {
c4e390
+      grub_free (filename);
c4e390
+      return 0;
c4e390
+    }
c4e390
+
c4e390
   /* Make sure the byte order of the UTF16 string is correct.  */
c4e390
   for (i = 0; i < grub_be_to_cpu16 (catkey->namelen); i++)
c4e390
     {
c4e390
-      catkey->name[i] = grub_be_to_cpu16 (catkey->name[i]);
c4e390
+      keyname[i] = grub_be_to_cpu16 (catkey->name[i]);
c4e390
 
c4e390
-      if (catkey->name[i] == '/')
c4e390
-	catkey->name[i] = ':';
c4e390
+      if (keyname[i] == '/')
c4e390
+	keyname[i] = ':';
c4e390
 
c4e390
       /* If the name is obviously invalid, skip this node.  */
c4e390
-      if (catkey->name[i] == 0)
c4e390
-	return 0;
c4e390
+      if (keyname[i] == 0)
c4e390
+	{
c4e390
+	  grub_free (keyname);
c4e390
+	  grub_free (filename);
c4e390
+	  return 0;
c4e390
+	}
c4e390
     }
c4e390
 
c4e390
-  *grub_utf16_to_utf8 ((grub_uint8_t *) filename, catkey->name,
c4e390
+  *grub_utf16_to_utf8 ((grub_uint8_t *) filename, keyname,
c4e390
 		       grub_be_to_cpu16 (catkey->namelen)) = '\0';
c4e390
-
c4e390
-  /* Restore the byte order to what it was previously.  */
c4e390
-  for (i = 0; i < grub_be_to_cpu16 (catkey->namelen); i++)
c4e390
-    {
c4e390
-      if (catkey->name[i] == ':')
c4e390
-	catkey->name[i] = '/';
c4e390
-      catkey->name[i] = grub_be_to_cpu16 (catkey->name[i]);
c4e390
-    }
c4e390
+  grub_free (keyname);
c4e390
 
c4e390
   /* hfs+ is case insensitive.  */
c4e390
   if (! ctx->dir->data->case_sensitive)
c4e390
@@ -963,6 +968,7 @@ grub_hfsplus_label (grub_device_t device, char **label)
c4e390
   grub_disk_t disk = device->disk;
c4e390
   struct grub_hfsplus_catkey *catkey;
c4e390
   int i, label_len;
c4e390
+  grub_uint16_t *label_name;
c4e390
   struct grub_hfsplus_key_internal intern;
c4e390
   struct grub_hfsplus_btnode *node;
c4e390
   grub_disk_addr_t ptr;
c4e390
@@ -991,22 +997,41 @@ grub_hfsplus_label (grub_device_t device, char **label)
c4e390
     grub_hfsplus_btree_recptr (&data->catalog_tree, node, ptr);
c4e390
 
c4e390
   label_len = grub_be_to_cpu16 (catkey->namelen);
c4e390
+  label_name = grub_calloc (label_len, sizeof (*label_name));
c4e390
+  if (!label_name)
c4e390
+    {
c4e390
+      grub_free (node);
c4e390
+      grub_free (data);
c4e390
+      return grub_errno;
c4e390
+    }
c4e390
+
c4e390
   for (i = 0; i < label_len; i++)
c4e390
     {
c4e390
-      catkey->name[i] = grub_be_to_cpu16 (catkey->name[i]);
c4e390
+      label_name[i] = grub_be_to_cpu16 (catkey->name[i]);
c4e390
 
c4e390
       /* If the name is obviously invalid, skip this node.  */
c4e390
       if (catkey->name[i] == 0)
c4e390
-	return 0;
c4e390
+	{
c4e390
+	  grub_free (label_name);
c4e390
+	  grub_free (node);
c4e390
+	  grub_free (data);
c4e390
+	  return 0;
c4e390
+	}
c4e390
     }
c4e390
 
c4e390
-  *label = grub_malloc (label_len * GRUB_MAX_UTF8_PER_UTF16 + 1);
c4e390
+  *label = grub_calloc (label_len, GRUB_MAX_UTF8_PER_UTF16 + 1);
c4e390
   if (! *label)
c4e390
-    return grub_errno;
c4e390
+    {
c4e390
+      grub_free (label_name);
c4e390
+      grub_free (node);
c4e390
+      grub_free (data);
c4e390
+      return grub_errno;
c4e390
+    }
c4e390
 
c4e390
-  *grub_utf16_to_utf8 ((grub_uint8_t *) (*label), catkey->name,
c4e390
+  *grub_utf16_to_utf8 ((grub_uint8_t *) (*label), label_name,
c4e390
 		       label_len) = '\0';
c4e390
 
c4e390
+  grub_free (label_name);
c4e390
   grub_free (node);
c4e390
   grub_free (data);
c4e390
 
c4e390
diff --git a/grub-core/fs/iso9660.c b/grub-core/fs/iso9660.c
c4e390
index 6a6677337d7..2fe433ceb54 100644
c4e390
--- a/grub-core/fs/iso9660.c
c4e390
+++ b/grub-core/fs/iso9660.c
c4e390
@@ -331,7 +331,7 @@ grub_iso9660_convert_string (grub_uint8_t *us, int len)
c4e390
   int i;
c4e390
   grub_uint16_t t[MAX_NAMELEN / 2 + 1];
c4e390
 
c4e390
-  p = grub_malloc (len * GRUB_MAX_UTF8_PER_UTF16 + 1);
c4e390
+  p = grub_calloc (len, GRUB_MAX_UTF8_PER_UTF16 + 1);
c4e390
   if (! p)
c4e390
     return NULL;
c4e390
 
c4e390
diff --git a/grub-core/fs/ntfs.c b/grub-core/fs/ntfs.c
c4e390
index d3a91f5d791..7997fc2c323 100644
c4e390
--- a/grub-core/fs/ntfs.c
c4e390
+++ b/grub-core/fs/ntfs.c
c4e390
@@ -556,8 +556,8 @@ get_utf8 (grub_uint8_t *in, grub_size_t len)
c4e390
   grub_uint16_t *tmp;
c4e390
   grub_size_t i;
c4e390
 
c4e390
-  buf = grub_malloc (len * GRUB_MAX_UTF8_PER_UTF16 + 1);
c4e390
-  tmp = grub_malloc (len * sizeof (tmp[0]));
c4e390
+  buf = grub_calloc (len, GRUB_MAX_UTF8_PER_UTF16 + 1);
c4e390
+  tmp = grub_calloc (len, sizeof (tmp[0]));
c4e390
   if (!buf || !tmp)
c4e390
     {
c4e390
       grub_free (buf);
c4e390
diff --git a/grub-core/fs/sfs.c b/grub-core/fs/sfs.c
c4e390
index 6c821504876..754cad880f5 100644
c4e390
--- a/grub-core/fs/sfs.c
c4e390
+++ b/grub-core/fs/sfs.c
c4e390
@@ -261,7 +261,7 @@ grub_sfs_read_block (grub_fshelp_node_t node, grub_disk_addr_t fileblock)
c4e390
       node->next_extent = node->block;
c4e390
       node->cache_size = 0;
c4e390
 
c4e390
-      node->cache = grub_malloc (sizeof (node->cache[0]) * cache_size);
c4e390
+      node->cache = grub_calloc (cache_size, sizeof (node->cache[0]));
c4e390
       if (!node->cache)
c4e390
 	{
c4e390
 	  grub_errno = 0;
c4e390
diff --git a/grub-core/fs/tar.c b/grub-core/fs/tar.c
c4e390
index 39bf197aabe..4864451e19b 100644
c4e390
--- a/grub-core/fs/tar.c
c4e390
+++ b/grub-core/fs/tar.c
c4e390
@@ -120,7 +120,7 @@ grub_cpio_find_file (struct grub_archelp_data *data, char **name,
c4e390
 	  if (data->linkname_alloc < linksize + 1)
c4e390
 	    {
c4e390
 	      char *n;
c4e390
-	      n = grub_malloc (2 * (linksize + 1));
c4e390
+	      n = grub_calloc (2, linksize + 1);
c4e390
 	      if (!n)
c4e390
 		return grub_errno;
c4e390
 	      grub_free (data->linkname);
c4e390
diff --git a/grub-core/fs/udf.c b/grub-core/fs/udf.c
c4e390
index fd412830c2b..488f35a3ee5 100644
c4e390
--- a/grub-core/fs/udf.c
c4e390
+++ b/grub-core/fs/udf.c
c4e390
@@ -836,7 +836,7 @@ read_string (const grub_uint8_t *raw, grub_size_t sz, char *outbuf)
c4e390
     {
c4e390
       unsigned i;
c4e390
       utf16len = sz - 1;
c4e390
-      utf16 = grub_malloc (utf16len * sizeof (utf16[0]));
c4e390
+      utf16 = grub_calloc (utf16len, sizeof (utf16[0]));
c4e390
       if (!utf16)
c4e390
 	return NULL;
c4e390
       for (i = 0; i < utf16len; i++)
c4e390
@@ -846,7 +846,7 @@ read_string (const grub_uint8_t *raw, grub_size_t sz, char *outbuf)
c4e390
     {
c4e390
       unsigned i;
c4e390
       utf16len = (sz - 1) / 2;
c4e390
-      utf16 = grub_malloc (utf16len * sizeof (utf16[0]));
c4e390
+      utf16 = grub_calloc (utf16len, sizeof (utf16[0]));
c4e390
       if (!utf16)
c4e390
 	return NULL;
c4e390
       for (i = 0; i < utf16len; i++)
c4e390
diff --git a/grub-core/fs/zfs/zfs.c b/grub-core/fs/zfs/zfs.c
c4e390
index cfb25c030de..3d7351de37c 100644
c4e390
--- a/grub-core/fs/zfs/zfs.c
c4e390
+++ b/grub-core/fs/zfs/zfs.c
c4e390
@@ -3253,7 +3253,7 @@ dnode_get_fullpath (const char *fullpath, struct subvolume *subvol,
c4e390
 	}
c4e390
       subvol->nkeys = 0;
c4e390
       zap_iterate (&keychain_dn, 8, count_zap_keys, &ctx, data);
c4e390
-      subvol->keyring = grub_zalloc (subvol->nkeys * sizeof (subvol->keyring[0]));
c4e390
+      subvol->keyring = grub_calloc (subvol->nkeys, sizeof (subvol->keyring[0]));
c4e390
       if (!subvol->keyring)
c4e390
 	{
c4e390
 	  grub_free (fsname);
c4e390
@@ -4250,7 +4250,7 @@ grub_zfs_embed (grub_device_t device __attribute__ ((unused)),
c4e390
   *nsectors = (VDEV_BOOT_SIZE >> GRUB_DISK_SECTOR_BITS);
c4e390
   if (*nsectors > max_nsectors)
c4e390
     *nsectors = max_nsectors;
c4e390
-  *sectors = grub_malloc (*nsectors * sizeof (**sectors));
c4e390
+  *sectors = grub_calloc (*nsectors, sizeof (**sectors));
c4e390
   if (!*sectors)
c4e390
     return grub_errno;
c4e390
   for (i = 0; i < *nsectors; i++)
c4e390
diff --git a/grub-core/gfxmenu/gui_string_util.c b/grub-core/gfxmenu/gui_string_util.c
c4e390
index a9a415e3129..ba1e1eab319 100644
c4e390
--- a/grub-core/gfxmenu/gui_string_util.c
c4e390
+++ b/grub-core/gfxmenu/gui_string_util.c
c4e390
@@ -55,7 +55,7 @@ canonicalize_path (const char *path)
c4e390
     if (*p == '/')
c4e390
       components++;
c4e390
 
c4e390
-  char **path_array = grub_malloc (components * sizeof (*path_array));
c4e390
+  char **path_array = grub_calloc (components, sizeof (*path_array));
c4e390
   if (! path_array)
c4e390
     return 0;
c4e390
 
c4e390
diff --git a/grub-core/gfxmenu/widget-box.c b/grub-core/gfxmenu/widget-box.c
c4e390
index b6060288914..470597ded2b 100644
c4e390
--- a/grub-core/gfxmenu/widget-box.c
c4e390
+++ b/grub-core/gfxmenu/widget-box.c
c4e390
@@ -303,10 +303,10 @@ grub_gfxmenu_create_box (const char *pixmaps_prefix,
c4e390
   box->content_height = 0;
c4e390
   box->raw_pixmaps =
c4e390
     (struct grub_video_bitmap **)
c4e390
-    grub_malloc (BOX_NUM_PIXMAPS * sizeof (struct grub_video_bitmap *));
c4e390
+    grub_calloc (BOX_NUM_PIXMAPS, sizeof (struct grub_video_bitmap *));
c4e390
   box->scaled_pixmaps =
c4e390
     (struct grub_video_bitmap **)
c4e390
-    grub_malloc (BOX_NUM_PIXMAPS * sizeof (struct grub_video_bitmap *));
c4e390
+    grub_calloc (BOX_NUM_PIXMAPS, sizeof (struct grub_video_bitmap *));
c4e390
 
c4e390
   /* Initialize all pixmap pointers to NULL so that proper destruction can
c4e390
      be performed if an error is encountered partway through construction.  */
c4e390
diff --git a/grub-core/io/gzio.c b/grub-core/io/gzio.c
c4e390
index 129209e37d0..daf514bc482 100644
c4e390
--- a/grub-core/io/gzio.c
c4e390
+++ b/grub-core/io/gzio.c
c4e390
@@ -542,7 +542,7 @@ huft_build (unsigned *b,	/* code lengths in bits (all assumed <= BMAX) */
c4e390
 	      z = 1 << j;	/* table entries for j-bit table */
c4e390
 
c4e390
 	      /* allocate and link in new table */
c4e390
-	      q = (struct huft *) grub_zalloc ((z + 1) * sizeof (struct huft));
c4e390
+	      q = (struct huft *) grub_calloc (z + 1, sizeof (struct huft));
c4e390
 	      if (! q)
c4e390
 		{
c4e390
 		  if (h)
c4e390
diff --git a/grub-core/kern/efi/efi.c b/grub-core/kern/efi/efi.c
c4e390
index 570535f78d0..4bd7ca210ad 100644
c4e390
--- a/grub-core/kern/efi/efi.c
c4e390
+++ b/grub-core/kern/efi/efi.c
c4e390
@@ -198,7 +198,7 @@ grub_efi_set_variable(const char *var, const grub_efi_guid_t *guid,
c4e390
 
c4e390
   len = grub_strlen (var);
c4e390
   len16 = len * GRUB_MAX_UTF16_PER_UTF8;
c4e390
-  var16 = grub_malloc ((len16 + 1) * sizeof (var16[0]));
c4e390
+  var16 = grub_calloc (len16 + 1, sizeof (var16[0]));
c4e390
   if (!var16)
c4e390
     return grub_errno;
c4e390
   len16 = grub_utf8_to_utf16 (var16, len16, (grub_uint8_t *) var, len, NULL);
c4e390
@@ -233,7 +233,7 @@ grub_efi_get_variable (const char *var, const grub_efi_guid_t *guid,
c4e390
 
c4e390
   len = grub_strlen (var);
c4e390
   len16 = len * GRUB_MAX_UTF16_PER_UTF8;
c4e390
-  var16 = grub_malloc ((len16 + 1) * sizeof (var16[0]));
c4e390
+  var16 = grub_calloc (len16 + 1, sizeof (var16[0]));
c4e390
   if (!var16)
c4e390
     return NULL;
c4e390
   len16 = grub_utf8_to_utf16 (var16, len16, (grub_uint8_t *) var, len, NULL);
c4e390
@@ -365,6 +365,7 @@ grub_efi_get_filename (grub_efi_device_path_t *dp0)
c4e390
 	{
c4e390
 	  grub_efi_file_path_device_path_t *fp;
c4e390
 	  grub_efi_uint16_t len;
c4e390
+	  grub_efi_char16_t *dup_name;
c4e390
 
c4e390
 	  *p++ = '/';
c4e390
 
c4e390
@@ -372,7 +373,16 @@ grub_efi_get_filename (grub_efi_device_path_t *dp0)
c4e390
 		 / sizeof (grub_efi_char16_t));
c4e390
 	  fp = (grub_efi_file_path_device_path_t *) dp;
c4e390
 
c4e390
-	  p = (char *) grub_utf16_to_utf8 ((unsigned char *) p, fp->path_name, len);
c4e390
+	  dup_name = grub_calloc (len, sizeof (*dup_name));
c4e390
+	  if (!dup_name)
c4e390
+	    {
c4e390
+	      grub_free (name);
c4e390
+	      return NULL;
c4e390
+	    }
c4e390
+	  p = (char *) grub_utf16_to_utf8 ((unsigned char *) p,
c4e390
+					    grub_memcpy (dup_name, fp->path_name, len * sizeof (*dup_name)),
c4e390
+					    len);
c4e390
+	  grub_free (dup_name);
c4e390
 	}
c4e390
 
c4e390
       dp = GRUB_EFI_NEXT_DEVICE_PATH (dp);
c4e390
@@ -862,9 +872,20 @@ grub_efi_print_device_path (grub_efi_device_path_t *dp)
c4e390
 		fp = (grub_efi_file_path_device_path_t *) dp;
c4e390
 		buf = grub_malloc ((len - 4) * 2 + 1);
c4e390
 		if (buf)
c4e390
-		  *grub_utf16_to_utf8 (buf, fp->path_name,
c4e390
+		  {
c4e390
+		    grub_efi_char16_t *dup_name = grub_malloc (len - 4);
c4e390
+		    if (!dup_name)
c4e390
+		      {
c4e390
+			grub_errno = GRUB_ERR_NONE;
c4e390
+			grub_printf ("/File((null))");
c4e390
+			grub_free (buf);
c4e390
+			break;
c4e390
+		      }
c4e390
+		    *grub_utf16_to_utf8 (buf, grub_memcpy (dup_name, fp->path_name, len - 4),
c4e390
 				       (len - 4) / sizeof (grub_efi_char16_t))
c4e390
-		    = '\0';
c4e390
+		      = '\0';
c4e390
+		    grub_free (dup_name);
c4e390
+		  }
c4e390
 		else
c4e390
 		  grub_errno = GRUB_ERR_NONE;
c4e390
 		grub_printf ("/File(%s)", buf);
c4e390
diff --git a/grub-core/kern/emu/hostdisk.c b/grub-core/kern/emu/hostdisk.c
c4e390
index 44b0fcbb1e5..419073a0391 100644
c4e390
--- a/grub-core/kern/emu/hostdisk.c
c4e390
+++ b/grub-core/kern/emu/hostdisk.c
c4e390
@@ -615,7 +615,7 @@ static char *
c4e390
 grub_util_path_concat_real (size_t n, int ext, va_list ap)
c4e390
 {
c4e390
   size_t totlen = 0;
c4e390
-  char **l = xmalloc ((n + ext) * sizeof (l[0]));
c4e390
+  char **l = xcalloc (n + ext, sizeof (l[0]));
c4e390
   char *r, *p, *pi;
c4e390
   size_t i;
c4e390
   int first = 1;
c4e390
diff --git a/grub-core/kern/fs.c b/grub-core/kern/fs.c
c4e390
index 9085895b6fe..23f4301c026 100644
c4e390
--- a/grub-core/kern/fs.c
c4e390
+++ b/grub-core/kern/fs.c
c4e390
@@ -151,7 +151,7 @@ grub_fs_blocklist_open (grub_file_t file, const char *name)
c4e390
   while (p);
c4e390
 
c4e390
   /* Allocate a block list.  */
c4e390
-  blocks = grub_zalloc (sizeof (struct grub_fs_block) * (num + 1));
c4e390
+  blocks = grub_calloc (num + 1, sizeof (struct grub_fs_block));
c4e390
   if (! blocks)
c4e390
     return 0;
c4e390
 
c4e390
diff --git a/grub-core/kern/misc.c b/grub-core/kern/misc.c
c4e390
index d0ca2ee603b..8b4a78b35be 100644
c4e390
--- a/grub-core/kern/misc.c
c4e390
+++ b/grub-core/kern/misc.c
c4e390
@@ -882,7 +882,7 @@ parse_printf_args (const char *fmt0, struct printf_args *args,
c4e390
     args->ptr = args->prealloc;
c4e390
   else
c4e390
     {
c4e390
-      args->ptr = grub_malloc (args->count * sizeof (args->ptr[0]));
c4e390
+      args->ptr = grub_calloc (args->count, sizeof (args->ptr[0]));
c4e390
       if (!args->ptr)
c4e390
 	{
c4e390
 	  grub_errno = GRUB_ERR_NONE;
c4e390
diff --git a/grub-core/kern/parser.c b/grub-core/kern/parser.c
c4e390
index b9bd12352db..5de8559e777 100644
c4e390
--- a/grub-core/kern/parser.c
c4e390
+++ b/grub-core/kern/parser.c
c4e390
@@ -213,7 +213,7 @@ grub_parser_split_cmdline (const char *cmdline,
c4e390
     return grub_errno;
c4e390
   grub_memcpy (args, buffer, bp - buffer);
c4e390
 
c4e390
-  *argv = grub_malloc (sizeof (char *) * (*argc + 1));
c4e390
+  *argv = grub_calloc (*argc + 1, sizeof (char *));
c4e390
   if (!*argv)
c4e390
     {
c4e390
       grub_free (args);
c4e390
diff --git a/grub-core/kern/uboot/uboot.c b/grub-core/kern/uboot/uboot.c
c4e390
index 6800a4beb1c..948b08b9579 100644
c4e390
--- a/grub-core/kern/uboot/uboot.c
c4e390
+++ b/grub-core/kern/uboot/uboot.c
c4e390
@@ -168,7 +168,7 @@ grub_uboot_dev_enum (void)
c4e390
     return num_devices;
c4e390
 
c4e390
   max_devices = 2;
c4e390
-  enum_devices = grub_malloc (sizeof(struct device_info) * max_devices);
c4e390
+  enum_devices = grub_calloc (max_devices, sizeof(struct device_info));
c4e390
   if (!enum_devices)
c4e390
     return 0;
c4e390
 
c4e390
diff --git a/grub-core/lib/libgcrypt/cipher/ac.c b/grub-core/lib/libgcrypt/cipher/ac.c
c4e390
index f5e946a2d8f..63f6fcd11ef 100644
c4e390
--- a/grub-core/lib/libgcrypt/cipher/ac.c
c4e390
+++ b/grub-core/lib/libgcrypt/cipher/ac.c
c4e390
@@ -185,7 +185,7 @@ ac_data_mpi_copy (gcry_ac_mpi_t *data_mpis, unsigned int data_mpis_n,
c4e390
   gcry_mpi_t mpi;
c4e390
   char *label;
c4e390
 
c4e390
-  data_mpis_new = gcry_malloc (sizeof (*data_mpis_new) * data_mpis_n);
c4e390
+  data_mpis_new = gcry_calloc (data_mpis_n, sizeof (*data_mpis_new));
c4e390
   if (! data_mpis_new)
c4e390
     {
c4e390
       err = gcry_error_from_errno (errno);
c4e390
@@ -572,7 +572,7 @@ _gcry_ac_data_to_sexp (gcry_ac_data_t data, gcry_sexp_t *sexp,
c4e390
     }
c4e390
 
c4e390
   /* Add MPI list.  */
c4e390
-  arg_list = gcry_malloc (sizeof (*arg_list) * (data_n + 1));
c4e390
+  arg_list = gcry_calloc (data_n + 1, sizeof (*arg_list));
c4e390
   if (! arg_list)
c4e390
     {
c4e390
       err = gcry_error_from_errno (errno);
c4e390
@@ -1283,7 +1283,7 @@ ac_data_construct (const char *identifier, int include_flags,
c4e390
   /* We build a list of arguments to pass to
c4e390
      gcry_sexp_build_array().  */
c4e390
   data_length = _gcry_ac_data_length (data);
c4e390
-  arg_list = gcry_malloc (sizeof (*arg_list) * (data_length * 2));
c4e390
+  arg_list = gcry_calloc (data_length, sizeof (*arg_list) * 2);
c4e390
   if (! arg_list)
c4e390
     {
c4e390
       err = gcry_error_from_errno (errno);
c4e390
@@ -1593,7 +1593,7 @@ _gcry_ac_key_pair_generate (gcry_ac_handle_t handle, unsigned int nbits,
c4e390
 	arg_list_n += 2;
c4e390
 
c4e390
   /* Allocate list.  */
c4e390
-  arg_list = gcry_malloc (sizeof (*arg_list) * arg_list_n);
c4e390
+  arg_list = gcry_calloc (arg_list_n, sizeof (*arg_list));
c4e390
   if (! arg_list)
c4e390
     {
c4e390
       err = gcry_error_from_errno (errno);
c4e390
diff --git a/grub-core/lib/libgcrypt/cipher/primegen.c b/grub-core/lib/libgcrypt/cipher/primegen.c
c4e390
index 2788e349fa9..b12e79b1922 100644
c4e390
--- a/grub-core/lib/libgcrypt/cipher/primegen.c
c4e390
+++ b/grub-core/lib/libgcrypt/cipher/primegen.c
c4e390
@@ -383,7 +383,7 @@ prime_generate_internal (int need_q_factor,
c4e390
     }
c4e390
 
c4e390
   /* Allocate an array to track pool usage. */
c4e390
-  pool_in_use = gcry_malloc (n * sizeof *pool_in_use);
c4e390
+  pool_in_use = gcry_calloc (n, sizeof *pool_in_use);
c4e390
   if (!pool_in_use)
c4e390
     {
c4e390
       err = gpg_err_code_from_errno (errno);
c4e390
@@ -765,7 +765,7 @@ gen_prime (unsigned int nbits, int secret, int randomlevel,
c4e390
   if (nbits < 16)
c4e390
     log_fatal ("can't generate a prime with less than %d bits\n", 16);
c4e390
 
c4e390
-  mods = gcry_xmalloc( no_of_small_prime_numbers * sizeof *mods );
c4e390
+  mods = gcry_xcalloc( no_of_small_prime_numbers, sizeof *mods);
c4e390
   /* Make nbits fit into gcry_mpi_t implementation. */
c4e390
   val_2  = mpi_alloc_set_ui( 2 );
c4e390
   val_3 = mpi_alloc_set_ui( 3);
c4e390
diff --git a/grub-core/lib/libgcrypt/cipher/pubkey.c b/grub-core/lib/libgcrypt/cipher/pubkey.c
c4e390
index 910982141e0..ca087ad75b9 100644
c4e390
--- a/grub-core/lib/libgcrypt/cipher/pubkey.c
c4e390
+++ b/grub-core/lib/libgcrypt/cipher/pubkey.c
c4e390
@@ -2941,7 +2941,7 @@ gcry_pk_encrypt (gcry_sexp_t *r_ciph, gcry_sexp_t s_data, gcry_sexp_t s_pkey)
c4e390
        * array to a format string, so we have to do it this way :-(.  */
c4e390
       /* FIXME: There is now such a format specifier, so we can
c4e390
          change the code to be more clear. */
c4e390
-      arg_list = malloc (nelem * sizeof *arg_list);
c4e390
+      arg_list = calloc (nelem, sizeof *arg_list);
c4e390
       if (!arg_list)
c4e390
         {
c4e390
           rc = gpg_err_code_from_syserror ();
c4e390
@@ -3233,7 +3233,7 @@ gcry_pk_sign (gcry_sexp_t *r_sig, gcry_sexp_t s_hash, gcry_sexp_t s_skey)
c4e390
         }
c4e390
       strcpy (p, "))");
c4e390
 
c4e390
-      arg_list = malloc (nelem * sizeof *arg_list);
c4e390
+      arg_list = calloc (nelem, sizeof *arg_list);
c4e390
       if (!arg_list)
c4e390
         {
c4e390
           rc = gpg_err_code_from_syserror ();
c4e390
diff --git a/grub-core/lib/priority_queue.c b/grub-core/lib/priority_queue.c
c4e390
index 659be0b7f40..7d5e7c05aab 100644
c4e390
--- a/grub-core/lib/priority_queue.c
c4e390
+++ b/grub-core/lib/priority_queue.c
c4e390
@@ -92,7 +92,7 @@ grub_priority_queue_new (grub_size_t elsize,
c4e390
 {
c4e390
   struct grub_priority_queue *ret;
c4e390
   void *els;
c4e390
-  els = grub_malloc (elsize * 8);
c4e390
+  els = grub_calloc (8, elsize);
c4e390
   if (!els)
c4e390
     return 0;
c4e390
   ret = (struct grub_priority_queue *) grub_malloc (sizeof (*ret));
c4e390
diff --git a/grub-core/lib/reed_solomon.c b/grub-core/lib/reed_solomon.c
c4e390
index 7263cbc0463..9b12f29e1d9 100644
c4e390
--- a/grub-core/lib/reed_solomon.c
c4e390
+++ b/grub-core/lib/reed_solomon.c
c4e390
@@ -20,6 +20,7 @@
c4e390
 #include <stdio.h>
c4e390
 #include <string.h>
c4e390
 #include <stdlib.h>
c4e390
+#define xcalloc calloc
c4e390
 #define xmalloc malloc
c4e390
 #define grub_memset memset
c4e390
 #define grub_memcpy memcpy
c4e390
@@ -158,11 +159,9 @@ rs_encode (gf_single_t *data, grub_size_t s, grub_size_t rs)
c4e390
   gf_single_t *rs_polynomial;
c4e390
   int i, j;
c4e390
   gf_single_t *m;
c4e390
-  m = xmalloc ((s + rs) * sizeof (gf_single_t));
c4e390
+  m = xcalloc (s + rs, sizeof (gf_single_t));
c4e390
   grub_memcpy (m, data, s * sizeof (gf_single_t));
c4e390
-  grub_memset (m + s, 0, rs * sizeof (gf_single_t));
c4e390
-  rs_polynomial = xmalloc ((rs + 1) * sizeof (gf_single_t));
c4e390
-  grub_memset (rs_polynomial, 0, (rs + 1) * sizeof (gf_single_t));
c4e390
+  rs_polynomial = xcalloc (rs + 1, sizeof (gf_single_t));
c4e390
   rs_polynomial[rs] = 1;
c4e390
   /* Multiply with X - a^r */
c4e390
   for (j = 0; j < rs; j++)
c4e390
diff --git a/grub-core/lib/relocator.c b/grub-core/lib/relocator.c
c4e390
index f759c7f41f4..7ea72069a45 100644
c4e390
--- a/grub-core/lib/relocator.c
c4e390
+++ b/grub-core/lib/relocator.c
c4e390
@@ -495,9 +495,9 @@ malloc_in_range (struct grub_relocator *rel,
c4e390
   }
c4e390
 #endif
c4e390
 
c4e390
-  eventt = grub_malloc (maxevents * sizeof (events[0]));
c4e390
+  eventt = grub_calloc (maxevents, sizeof (events[0]));
c4e390
   counter = grub_malloc ((DIGITSORT_MASK + 2) * sizeof (counter[0]));
c4e390
-  events = grub_malloc (maxevents * sizeof (events[0]));
c4e390
+  events = grub_calloc (maxevents, sizeof (events[0]));
c4e390
   if (!events || !eventt || !counter)
c4e390
     {
c4e390
       grub_dprintf ("relocator", "events or counter allocation failed %d\n",
c4e390
@@ -953,7 +953,7 @@ malloc_in_range (struct grub_relocator *rel,
c4e390
 #endif
c4e390
     unsigned cural = 0;
c4e390
     int oom = 0;
c4e390
-    res->subchunks = grub_malloc (sizeof (res->subchunks[0]) * nallocs);
c4e390
+    res->subchunks = grub_calloc (nallocs, sizeof (res->subchunks[0]));
c4e390
     if (!res->subchunks)
c4e390
       oom = 1;
c4e390
     res->nsubchunks = nallocs;
c4e390
@@ -1552,8 +1552,8 @@ grub_relocator_prepare_relocs (struct grub_relocator *rel, grub_addr_t addr,
c4e390
 	    count[(chunk->src & 0xff) + 1]++;
c4e390
 	  }
c4e390
     }
c4e390
-    from = grub_malloc (nchunks * sizeof (sorted[0]));
c4e390
-    to = grub_malloc (nchunks * sizeof (sorted[0]));
c4e390
+    from = grub_calloc (nchunks, sizeof (sorted[0]));
c4e390
+    to = grub_calloc (nchunks, sizeof (sorted[0]));
c4e390
     if (!from || !to)
c4e390
       {
c4e390
 	grub_free (from);
c4e390
diff --git a/grub-core/loader/arm/linux.c b/grub-core/loader/arm/linux.c
c4e390
index 62cbe75d34e..1b195e0899e 100644
c4e390
--- a/grub-core/loader/arm/linux.c
c4e390
+++ b/grub-core/loader/arm/linux.c
c4e390
@@ -79,7 +79,7 @@ linux_prepare_atag (void)
c4e390
 
c4e390
   /* some place for cmdline, initrd and terminator.  */
c4e390
   tmp_size = get_atag_size (atag_orig) + 20 + (arg_size) / 4;
c4e390
-  tmp_atag = grub_malloc (tmp_size * sizeof (grub_uint32_t));
c4e390
+  tmp_atag = grub_calloc (tmp_size, sizeof (grub_uint32_t));
c4e390
   if (!tmp_atag)
c4e390
     return grub_errno;
c4e390
 
c4e390
diff --git a/grub-core/loader/efi/chainloader.c b/grub-core/loader/efi/chainloader.c
c4e390
index db1ffeefc93..3d600fa6bd5 100644
c4e390
--- a/grub-core/loader/efi/chainloader.c
c4e390
+++ b/grub-core/loader/efi/chainloader.c
c4e390
@@ -119,18 +119,23 @@ static void
c4e390
 copy_file_path (grub_efi_file_path_device_path_t *fp,
c4e390
 		const char *str, grub_efi_uint16_t len)
c4e390
 {
c4e390
-  grub_efi_char16_t *p;
c4e390
+  grub_efi_char16_t *p, *path_name;
c4e390
   grub_efi_uint16_t size;
c4e390
 
c4e390
   fp->header.type = GRUB_EFI_MEDIA_DEVICE_PATH_TYPE;
c4e390
   fp->header.subtype = GRUB_EFI_FILE_PATH_DEVICE_PATH_SUBTYPE;
c4e390
 
c4e390
-  size = grub_utf8_to_utf16 (fp->path_name, len * GRUB_MAX_UTF16_PER_UTF8,
c4e390
+  path_name = grub_calloc (len, GRUB_MAX_UTF16_PER_UTF8 * sizeof (*path_name));
c4e390
+  if (!path_name)
c4e390
+    return;
c4e390
+
c4e390
+  size = grub_utf8_to_utf16 (path_name, len * GRUB_MAX_UTF16_PER_UTF8,
c4e390
 			     (const grub_uint8_t *) str, len, 0);
c4e390
-  for (p = fp->path_name; p < fp->path_name + size; p++)
c4e390
+  for (p = path_name; p < path_name + size; p++)
c4e390
     if (*p == '/')
c4e390
       *p = '\\';
c4e390
 
c4e390
+  grub_memcpy (fp->path_name, path_name, size * sizeof (*fp->path_name));
c4e390
   /* File Path is NULL terminated */
c4e390
   fp->path_name[size++] = '\0';
c4e390
   fp->header.length = size * sizeof (grub_efi_char16_t) + sizeof (*fp);
c4e390
diff --git a/grub-core/loader/i386/bsdXX.c b/grub-core/loader/i386/bsdXX.c
c4e390
index 9e36cd4b651..6c8906fe878 100644
c4e390
--- a/grub-core/loader/i386/bsdXX.c
c4e390
+++ b/grub-core/loader/i386/bsdXX.c
c4e390
@@ -48,7 +48,7 @@ read_headers (grub_file_t file, const char *filename, Elf_Ehdr *e, char **shdr)
c4e390
   if (e->e_ident[EI_CLASS] != SUFFIX (ELFCLASS))
c4e390
     return grub_error (GRUB_ERR_BAD_OS, N_("invalid arch-dependent ELF magic"));
c4e390
 
c4e390
-  *shdr = grub_malloc (e->e_shnum * e->e_shentsize);
c4e390
+  *shdr = grub_calloc (e->e_shnum, e->e_shentsize);
c4e390
   if (! *shdr)
c4e390
     return grub_errno;
c4e390
 
c4e390
diff --git a/grub-core/loader/i386/xnu.c b/grub-core/loader/i386/xnu.c
c4e390
index e83e1e9725d..875048e1353 100644
c4e390
--- a/grub-core/loader/i386/xnu.c
c4e390
+++ b/grub-core/loader/i386/xnu.c
c4e390
@@ -292,7 +292,7 @@ grub_xnu_devprop_add_property_utf8 (struct grub_xnu_devprop_device_descriptor *d
c4e390
     return grub_errno;
c4e390
 
c4e390
   len = grub_strlen (name);
c4e390
-  utf16 = grub_malloc (sizeof (grub_uint16_t) * len);
c4e390
+  utf16 = grub_calloc (len, sizeof (grub_uint16_t));
c4e390
   if (!utf16)
c4e390
     {
c4e390
       grub_free (utf8);
c4e390
@@ -328,7 +328,7 @@ grub_xnu_devprop_add_property_utf16 (struct grub_xnu_devprop_device_descriptor *
c4e390
   grub_uint16_t *utf16;
c4e390
   grub_err_t err;
c4e390
 
c4e390
-  utf16 = grub_malloc (sizeof (grub_uint16_t) * namelen);
c4e390
+  utf16 = grub_calloc (namelen, sizeof (grub_uint16_t));
c4e390
   if (!utf16)
c4e390
     return grub_errno;
c4e390
   grub_memcpy (utf16, name, sizeof (grub_uint16_t) * namelen);
c4e390
diff --git a/grub-core/loader/macho.c b/grub-core/loader/macho.c
c4e390
index 59b195e27ea..f61341af515 100644
c4e390
--- a/grub-core/loader/macho.c
c4e390
+++ b/grub-core/loader/macho.c
c4e390
@@ -97,7 +97,7 @@ grub_macho_file (grub_file_t file, const char *filename, int is_64bit)
c4e390
       if (grub_file_seek (macho->file, sizeof (struct grub_macho_fat_header))
c4e390
 	  == (grub_off_t) -1)
c4e390
 	goto fail;
c4e390
-      archs = grub_malloc (sizeof (struct grub_macho_fat_arch) * narchs);
c4e390
+      archs = grub_calloc (narchs, sizeof (struct grub_macho_fat_arch));
c4e390
       if (!archs)
c4e390
 	goto fail;
c4e390
       if (grub_file_read (macho->file, archs,
c4e390
diff --git a/grub-core/loader/multiboot_elfxx.c b/grub-core/loader/multiboot_elfxx.c
c4e390
index 9dc21a1ba48..c0ff1239dbf 100644
c4e390
--- a/grub-core/loader/multiboot_elfxx.c
c4e390
+++ b/grub-core/loader/multiboot_elfxx.c
c4e390
@@ -164,7 +164,7 @@ CONCAT(grub_multiboot_load_elf, XX) (grub_file_t file, const char *filename, voi
c4e390
     {
c4e390
       grub_uint8_t *shdr, *shdrptr;
c4e390
 
c4e390
-      shdr = grub_malloc (ehdr->e_shnum * ehdr->e_shentsize);
c4e390
+      shdr = grub_calloc (ehdr->e_shnum, ehdr->e_shentsize);
c4e390
       if (!shdr)
c4e390
 	return grub_errno;
c4e390
       
c4e390
diff --git a/grub-core/loader/xnu.c b/grub-core/loader/xnu.c
c4e390
index faffccc9744..fdf61b6f9f7 100644
c4e390
--- a/grub-core/loader/xnu.c
c4e390
+++ b/grub-core/loader/xnu.c
c4e390
@@ -791,7 +791,7 @@ grub_cmd_xnu_mkext (grub_command_t cmd __attribute__ ((unused)),
c4e390
   if (grub_be_to_cpu32 (head.magic) == GRUB_MACHO_FAT_MAGIC)
c4e390
     {
c4e390
       narchs = grub_be_to_cpu32 (head.nfat_arch);
c4e390
-      archs = grub_malloc (sizeof (struct grub_macho_fat_arch) * narchs);
c4e390
+      archs = grub_calloc (narchs, sizeof (struct grub_macho_fat_arch));
c4e390
       if (! archs)
c4e390
 	{
c4e390
 	  grub_file_close (file);
c4e390
diff --git a/grub-core/mmap/mmap.c b/grub-core/mmap/mmap.c
c4e390
index 6a31cbae325..57b4e9a72a9 100644
c4e390
--- a/grub-core/mmap/mmap.c
c4e390
+++ b/grub-core/mmap/mmap.c
c4e390
@@ -143,9 +143,9 @@ grub_mmap_iterate (grub_memory_hook_t hook, void *hook_data)
c4e390
 
c4e390
   /* Initialize variables. */
c4e390
   ctx.scanline_events = (struct grub_mmap_scan *)
c4e390
-    grub_malloc (sizeof (struct grub_mmap_scan) * 2 * mmap_num);
c4e390
+    grub_calloc (mmap_num, sizeof (struct grub_mmap_scan) * 2);
c4e390
 
c4e390
-  present = grub_zalloc (sizeof (present[0]) * current_priority);
c4e390
+  present = grub_calloc (current_priority, sizeof (present[0]));
c4e390
 
c4e390
   if (! ctx.scanline_events || !present)
c4e390
     {
c4e390
diff --git a/grub-core/net/bootp.c b/grub-core/net/bootp.c
c4e390
index 249ca0c2dc6..4cfb3908031 100644
c4e390
--- a/grub-core/net/bootp.c
c4e390
+++ b/grub-core/net/bootp.c
c4e390
@@ -1338,7 +1338,7 @@ grub_cmd_bootp (struct grub_command *cmd __attribute__ ((unused)),
c4e390
   if (ncards == 0)
c4e390
     return grub_error (GRUB_ERR_NET_NO_CARD, N_("no network card found"));
c4e390
 
c4e390
-  ifaces = grub_zalloc (ncards * sizeof (ifaces[0]));
c4e390
+  ifaces = grub_calloc (ncards, sizeof (ifaces[0]));
c4e390
   if (!ifaces)
c4e390
     return grub_errno;
c4e390
 
c4e390
diff --git a/grub-core/net/dns.c b/grub-core/net/dns.c
c4e390
index 0b771fb10a5..695a920ac44 100644
c4e390
--- a/grub-core/net/dns.c
c4e390
+++ b/grub-core/net/dns.c
c4e390
@@ -276,8 +276,8 @@ recv_hook (grub_net_udp_socket_t sock __attribute__ ((unused)),
c4e390
       ptr++;
c4e390
       ptr += 4;
c4e390
     }
c4e390
-  *data->addresses = grub_malloc (sizeof ((*data->addresses)[0])
c4e390
-				 * grub_cpu_to_be16 (head->ancount));
c4e390
+  *data->addresses = grub_calloc (grub_be_to_cpu16 (head->ancount),
c4e390
+				  sizeof ((*data->addresses)[0]));
c4e390
   if (!*data->addresses)
c4e390
     {
c4e390
       grub_errno = GRUB_ERR_NONE;
c4e390
@@ -397,8 +397,8 @@ recv_hook (grub_net_udp_socket_t sock __attribute__ ((unused)),
c4e390
       dns_cache[h].addresses = 0;
c4e390
       dns_cache[h].name = grub_strdup (data->oname);
c4e390
       dns_cache[h].naddresses = *data->naddresses;
c4e390
-      dns_cache[h].addresses = grub_malloc (*data->naddresses
c4e390
-					    * sizeof (dns_cache[h].addresses[0]));
c4e390
+      dns_cache[h].addresses = grub_calloc (*data->naddresses,
c4e390
+					    sizeof (dns_cache[h].addresses[0]));
c4e390
       dns_cache[h].limit_time = grub_get_time_ms () + 1000 * ttl_all;
c4e390
       if (!dns_cache[h].addresses || !dns_cache[h].name)
c4e390
 	{
c4e390
@@ -470,7 +470,7 @@ grub_net_dns_lookup (const char *name,
c4e390
 	}
c4e390
     }
c4e390
 
c4e390
-  sockets = grub_malloc (sizeof (sockets[0]) * n_servers);
c4e390
+  sockets = grub_calloc (n_servers, sizeof (sockets[0]));
c4e390
   if (!sockets)
c4e390
     return grub_errno;
c4e390
 
c4e390
diff --git a/grub-core/net/net.c b/grub-core/net/net.c
c4e390
index cfe4cb62760..80310ff4e7a 100644
c4e390
--- a/grub-core/net/net.c
c4e390
+++ b/grub-core/net/net.c
c4e390
@@ -353,8 +353,8 @@ grub_cmd_ipv6_autoconf (struct grub_command *cmd __attribute__ ((unused)),
c4e390
     ncards++;
c4e390
   }
c4e390
 
c4e390
-  ifaces = grub_zalloc (ncards * sizeof (ifaces[0]));
c4e390
-  slaacs = grub_zalloc (ncards * sizeof (slaacs[0]));
c4e390
+  ifaces = grub_calloc (ncards, sizeof (ifaces[0]));
c4e390
+  slaacs = grub_calloc (ncards, sizeof (slaacs[0]));
c4e390
   if (!ifaces || !slaacs)
c4e390
     {
c4e390
       grub_free (ifaces);
c4e390
diff --git a/grub-core/normal/charset.c b/grub-core/normal/charset.c
c4e390
index 3e4c337da74..33b8b9cae79 100644
c4e390
--- a/grub-core/normal/charset.c
c4e390
+++ b/grub-core/normal/charset.c
c4e390
@@ -203,7 +203,7 @@ grub_utf8_to_ucs4_alloc (const char *msg, grub_uint32_t **unicode_msg,
c4e390
 {
c4e390
   grub_size_t msg_len = grub_strlen (msg);
c4e390
 
c4e390
-  *unicode_msg = grub_malloc (msg_len * sizeof (grub_uint32_t));
c4e390
+  *unicode_msg = grub_calloc (msg_len, sizeof (grub_uint32_t));
c4e390
  
c4e390
   if (!*unicode_msg)
c4e390
     return -1;
c4e390
@@ -488,7 +488,7 @@ grub_unicode_aglomerate_comb (const grub_uint32_t *in, grub_size_t inlen,
c4e390
 	    }
c4e390
 	  else
c4e390
 	    {
c4e390
-	      n = grub_malloc (sizeof (n[0]) * (out->ncomb + 1));
c4e390
+	      n = grub_calloc (out->ncomb + 1, sizeof (n[0]));
c4e390
 	      if (!n)
c4e390
 		{
c4e390
 		  grub_errno = GRUB_ERR_NONE;
c4e390
@@ -842,7 +842,7 @@ grub_bidi_line_logical_to_visual (const grub_uint32_t *logical,
c4e390
       }							\
c4e390
   }
c4e390
 
c4e390
-  visual = grub_malloc (sizeof (visual[0]) * logical_len);
c4e390
+  visual = grub_calloc (logical_len, sizeof (visual[0]));
c4e390
   if (!visual)
c4e390
     return -1;
c4e390
 
c4e390
@@ -1154,8 +1154,8 @@ grub_bidi_logical_to_visual (const grub_uint32_t *logical,
c4e390
 {
c4e390
   const grub_uint32_t *line_start = logical, *ptr;
c4e390
   struct grub_unicode_glyph *visual_ptr;
c4e390
-  *visual_out = visual_ptr = grub_malloc (3 * sizeof (visual_ptr[0])
c4e390
-					  * (logical_len + 2));
c4e390
+  *visual_out = visual_ptr = grub_calloc (logical_len + 2,
c4e390
+					  3 * sizeof (visual_ptr[0]));
c4e390
   if (!visual_ptr)
c4e390
     return -1;
c4e390
   for (ptr = logical; ptr <= logical + logical_len; ptr++)
c4e390
diff --git a/grub-core/normal/cmdline.c b/grub-core/normal/cmdline.c
c4e390
index 204d15a4bb8..aa6fd85d791 100644
c4e390
--- a/grub-core/normal/cmdline.c
c4e390
+++ b/grub-core/normal/cmdline.c
c4e390
@@ -41,7 +41,7 @@ grub_err_t
c4e390
 grub_set_history (int newsize)
c4e390
 {
c4e390
   grub_uint32_t **old_hist_lines = hist_lines;
c4e390
-  hist_lines = grub_malloc (sizeof (grub_uint32_t *) * newsize);
c4e390
+  hist_lines = grub_calloc (newsize, sizeof (grub_uint32_t *));
c4e390
 
c4e390
   /* Copy the old lines into the new buffer.  */
c4e390
   if (old_hist_lines)
c4e390
@@ -114,7 +114,7 @@ static void
c4e390
 grub_history_set (int pos, grub_uint32_t *s, grub_size_t len)
c4e390
 {
c4e390
   grub_free (hist_lines[pos]);
c4e390
-  hist_lines[pos] = grub_malloc ((len + 1) * sizeof (grub_uint32_t));
c4e390
+  hist_lines[pos] = grub_calloc (len + 1, sizeof (grub_uint32_t));
c4e390
   if (!hist_lines[pos])
c4e390
     {
c4e390
       grub_print_error ();
c4e390
@@ -349,7 +349,7 @@ grub_cmdline_get (const char *prompt_translated)
c4e390
   char *ret;
c4e390
   unsigned nterms;
c4e390
 
c4e390
-  buf = grub_malloc (max_len * sizeof (grub_uint32_t));
c4e390
+  buf = grub_calloc (max_len, sizeof (grub_uint32_t));
c4e390
   if (!buf)
c4e390
     return 0;
c4e390
 
c4e390
@@ -377,7 +377,7 @@ grub_cmdline_get (const char *prompt_translated)
c4e390
     FOR_ACTIVE_TERM_OUTPUTS(cur)
c4e390
       nterms++;
c4e390
 
c4e390
-    cl_terms = grub_malloc (sizeof (cl_terms[0]) * nterms);
c4e390
+    cl_terms = grub_calloc (nterms, sizeof (cl_terms[0]));
c4e390
     if (!cl_terms)
c4e390
       {
c4e390
 	grub_free (buf);
c4e390
@@ -385,7 +385,7 @@ grub_cmdline_get (const char *prompt_translated)
c4e390
       }
c4e390
     cl_term_cur = cl_terms;
c4e390
 
c4e390
-    unicode_msg = grub_malloc (msg_len * sizeof (grub_uint32_t));
c4e390
+    unicode_msg = grub_calloc (msg_len, sizeof (grub_uint32_t));
c4e390
     if (!unicode_msg)
c4e390
       {
c4e390
 	grub_free (buf);
c4e390
@@ -494,7 +494,7 @@ grub_cmdline_get (const char *prompt_translated)
c4e390
 		grub_uint32_t *insert;
c4e390
 
c4e390
 		insertlen = grub_strlen (insertu8);
c4e390
-		insert = grub_malloc ((insertlen + 1) * sizeof (grub_uint32_t));
c4e390
+		insert = grub_calloc (insertlen + 1, sizeof (grub_uint32_t));
c4e390
 		if (!insert)
c4e390
 		  {
c4e390
 		    grub_free (insertu8);
c4e390
@@ -601,7 +601,7 @@ grub_cmdline_get (const char *prompt_translated)
c4e390
 
c4e390
 	      grub_free (kill_buf);
c4e390
 
c4e390
-	      kill_buf = grub_malloc ((n + 1) * sizeof(grub_uint32_t));
c4e390
+	      kill_buf = grub_calloc (n + 1, sizeof (grub_uint32_t));
c4e390
 	      if (grub_errno)
c4e390
 		{
c4e390
 		  grub_print_error ();
c4e390
diff --git a/grub-core/normal/menu_entry.c b/grub-core/normal/menu_entry.c
c4e390
index 62e5db1fef8..dc1ac1dd1e1 100644
c4e390
--- a/grub-core/normal/menu_entry.c
c4e390
+++ b/grub-core/normal/menu_entry.c
c4e390
@@ -95,8 +95,8 @@ init_line (struct screen *screen, struct line *linep)
c4e390
 {
c4e390
   linep->len = 0;
c4e390
   linep->max_len = 80;
c4e390
-  linep->buf = grub_malloc ((linep->max_len + 1) * sizeof (linep->buf[0]));
c4e390
-  linep->pos = grub_zalloc (screen->nterms * sizeof (linep->pos[0]));
c4e390
+  linep->buf = grub_calloc (linep->max_len + 1, sizeof (linep->buf[0]));
c4e390
+  linep->pos = grub_calloc (screen->nterms, sizeof (linep->pos[0]));
c4e390
   if (! linep->buf || !linep->pos)
c4e390
     {
c4e390
       grub_free (linep->buf);
c4e390
@@ -281,7 +281,7 @@ update_screen (struct screen *screen, struct per_term_screen *term_screen,
c4e390
 	  pos = linep->pos + (term_screen - screen->terms);
c4e390
 
c4e390
 	  if (!*pos)
c4e390
-	    *pos = grub_zalloc ((linep->len + 1) * sizeof (**pos));
c4e390
+	    *pos = grub_calloc (linep->len + 1, sizeof (**pos));
c4e390
 
c4e390
 	  if (i == region_start || linep == screen->lines + screen->line
c4e390
 	      || (i > region_start && mode == ALL_LINES))
c4e390
@@ -463,7 +463,7 @@ insert_string (struct screen *screen, const char *s, int update)
c4e390
 
c4e390
 	  /* Insert the string.  */
c4e390
 	  current_linep = screen->lines + screen->line;
c4e390
-	  unicode_msg = grub_malloc ((p - s) * sizeof (grub_uint32_t));
c4e390
+	  unicode_msg = grub_calloc (p - s, sizeof (grub_uint32_t));
c4e390
 
c4e390
 	  if (!unicode_msg)
c4e390
 	    return 0;
c4e390
@@ -1012,7 +1012,7 @@ complete (struct screen *screen, int continuous, int update)
c4e390
   if (completion_buffer.buf)
c4e390
     {
c4e390
       buflen = grub_strlen (completion_buffer.buf);
c4e390
-      ucs4 = grub_malloc (sizeof (grub_uint32_t) * (buflen + 1));
c4e390
+      ucs4 = grub_calloc (buflen + 1, sizeof (grub_uint32_t));
c4e390
       
c4e390
       if (!ucs4)
c4e390
 	{
c4e390
@@ -1254,7 +1254,7 @@ grub_menu_entry_run (grub_menu_entry_t entry)
c4e390
   for (i = 0; i < (unsigned) screen->num_lines; i++)
c4e390
     {
c4e390
       grub_free (screen->lines[i].pos);
c4e390
-      screen->lines[i].pos = grub_zalloc (screen->nterms * sizeof (screen->lines[i].pos[0]));
c4e390
+      screen->lines[i].pos = grub_calloc (screen->nterms, sizeof (screen->lines[i].pos[0]));
c4e390
       if (! screen->lines[i].pos)
c4e390
 	{
c4e390
 	  grub_print_error ();
c4e390
@@ -1263,7 +1263,7 @@ grub_menu_entry_run (grub_menu_entry_t entry)
c4e390
 	}
c4e390
     }
c4e390
 
c4e390
-  screen->terms = grub_zalloc (screen->nterms * sizeof (screen->terms[0]));
c4e390
+  screen->terms = grub_calloc (screen->nterms, sizeof (screen->terms[0]));
c4e390
   if (!screen->terms)
c4e390
     {
c4e390
       grub_print_error ();
c4e390
diff --git a/grub-core/normal/menu_text.c b/grub-core/normal/menu_text.c
c4e390
index 33b208bcf44..5019ffa6c63 100644
c4e390
--- a/grub-core/normal/menu_text.c
c4e390
+++ b/grub-core/normal/menu_text.c
c4e390
@@ -78,7 +78,7 @@ grub_print_message_indented_real (const char *msg, int margin_left,
c4e390
   grub_size_t msg_len = grub_strlen (msg) + 2;
c4e390
   int ret = 0;
c4e390
 
c4e390
-  unicode_msg = grub_malloc (msg_len * sizeof (grub_uint32_t));
c4e390
+  unicode_msg = grub_calloc (msg_len, sizeof (grub_uint32_t));
c4e390
  
c4e390
   if (!unicode_msg)
c4e390
     return 0;
c4e390
@@ -167,7 +167,7 @@ print_entry (int y, int highlight, grub_menu_entry_t entry,
c4e390
 
c4e390
   title = entry ? entry->title : "";
c4e390
   title_len = grub_strlen (title);
c4e390
-  unicode_title = grub_malloc (title_len * sizeof (*unicode_title));
c4e390
+  unicode_title = grub_calloc (title_len, sizeof (*unicode_title));
c4e390
   if (! unicode_title)
c4e390
     /* XXX How to show this error?  */
c4e390
     return;
c4e390
diff --git a/grub-core/normal/term.c b/grub-core/normal/term.c
c4e390
index 4c2238b2589..bbfd4c211e9 100644
c4e390
--- a/grub-core/normal/term.c
c4e390
+++ b/grub-core/normal/term.c
c4e390
@@ -264,7 +264,7 @@ grub_term_save_pos (void)
c4e390
   FOR_ACTIVE_TERM_OUTPUTS(cur)
c4e390
     cnt++;
c4e390
 
c4e390
-  ret = grub_malloc (cnt * sizeof (ret[0]));
c4e390
+  ret = grub_calloc (cnt, sizeof (ret[0]));
c4e390
   if (!ret)
c4e390
     return NULL;
c4e390
 
c4e390
@@ -1013,7 +1013,7 @@ grub_xnputs (const char *str, grub_size_t msg_len)
c4e390
 
c4e390
   grub_error_push ();
c4e390
 
c4e390
-  unicode_str = grub_malloc (msg_len * sizeof (grub_uint32_t));
c4e390
+  unicode_str = grub_calloc (msg_len, sizeof (grub_uint32_t));
c4e390
  
c4e390
   grub_error_pop ();
c4e390
 
c4e390
diff --git a/grub-core/osdep/linux/getroot.c b/grub-core/osdep/linux/getroot.c
c4e390
index 6a7784a4ea2..32fd962ec47 100644
c4e390
--- a/grub-core/osdep/linux/getroot.c
c4e390
+++ b/grub-core/osdep/linux/getroot.c
c4e390
@@ -168,7 +168,7 @@ grub_util_raid_getmembers (const char *name, int bootable)
c4e390
   if (ret != 0)
c4e390
     grub_util_error (_("ioctl GET_ARRAY_INFO error: %s"), strerror (errno));
c4e390
 
c4e390
-  devicelist = xmalloc ((info.nr_disks + 1) * sizeof (char *));
c4e390
+  devicelist = xcalloc (info.nr_disks + 1, sizeof (char *));
c4e390
 
c4e390
   for (i = 0, j = 0; j < info.nr_disks; i++)
c4e390
     {
c4e390
@@ -241,7 +241,7 @@ grub_find_root_devices_from_btrfs (const char *dir)
c4e390
       return NULL;
c4e390
     }
c4e390
 
c4e390
-  ret = xmalloc ((fsi.num_devices + 1) * sizeof (ret[0]));
c4e390
+  ret = xcalloc (fsi.num_devices + 1, sizeof (ret[0]));
c4e390
 
c4e390
   for (i = 1; i <= fsi.max_id && j < fsi.num_devices; i++)
c4e390
     {
c4e390
@@ -391,7 +391,7 @@ grub_find_root_devices_from_mountinfo (const char *dir, char **relroot)
c4e390
   if (! fp)
c4e390
     return NULL; /* fall through to other methods */
c4e390
 
c4e390
-  entries = xmalloc (entry_max * sizeof (*entries));
c4e390
+  entries = xcalloc (entry_max, sizeof (*entries));
c4e390
 
c4e390
   /* First, build a list of relevant visible mounts.  */
c4e390
   while (getline (&buf, &len, fp) > 0)
c4e390
diff --git a/grub-core/osdep/unix/config.c b/grub-core/osdep/unix/config.c
c4e390
index f4b0bb466f7..604af82e892 100644
c4e390
--- a/grub-core/osdep/unix/config.c
c4e390
+++ b/grub-core/osdep/unix/config.c
c4e390
@@ -89,7 +89,7 @@ grub_util_load_config (struct grub_util_config *cfg)
c4e390
   argv[0] = "sh";
c4e390
   argv[1] = "-c";
c4e390
 
c4e390
-  script = xmalloc (4 * strlen (cfgfile) + 300);
c4e390
+  script = xcalloc (4, strlen (cfgfile) + 300);
c4e390
 
c4e390
   ptr = script;
c4e390
   memcpy (ptr, ". '", 3);
c4e390
diff --git a/grub-core/osdep/windows/getroot.c b/grub-core/osdep/windows/getroot.c
c4e390
index 661d9546192..eada663b261 100644
c4e390
--- a/grub-core/osdep/windows/getroot.c
c4e390
+++ b/grub-core/osdep/windows/getroot.c
c4e390
@@ -59,7 +59,7 @@ grub_get_mount_point (const TCHAR *path)
c4e390
 
c4e390
   for (ptr = path; *ptr; ptr++);
c4e390
   allocsize = (ptr - path + 10) * 2;
c4e390
-  out = xmalloc (allocsize * sizeof (out[0]));
c4e390
+  out = xcalloc (allocsize, sizeof (out[0]));
c4e390
 
c4e390
   /* When pointing to EFI system partition GetVolumePathName fails
c4e390
      for ESP root and returns abberant information for everything
c4e390
diff --git a/grub-core/osdep/windows/hostdisk.c b/grub-core/osdep/windows/hostdisk.c
c4e390
index 9127e9263b1..959a87c157b 100644
c4e390
--- a/grub-core/osdep/windows/hostdisk.c
c4e390
+++ b/grub-core/osdep/windows/hostdisk.c
c4e390
@@ -111,7 +111,7 @@ grub_util_get_windows_path_real (const char *path)
c4e390
 
c4e390
   while (1)
c4e390
     {
c4e390
-      fpa = xmalloc (alloc * sizeof (fpa[0]));
c4e390
+      fpa = xcalloc (alloc, sizeof (fpa[0]));
c4e390
 
c4e390
       len = GetFullPathName (tpath, alloc, fpa, NULL);
c4e390
       if (len >= alloc)
c4e390
@@ -393,7 +393,7 @@ grub_util_fd_opendir (const char *name)
c4e390
   for (l = 0; name_windows[l]; l++);
c4e390
   for (l--; l >= 0 && (name_windows[l] == '\\' || name_windows[l] == '/'); l--);
c4e390
   l++;
c4e390
-  pattern = xmalloc ((l + 3) * sizeof (pattern[0]));
c4e390
+  pattern = xcalloc (l + 3, sizeof (pattern[0]));
c4e390
   memcpy (pattern, name_windows, l * sizeof (pattern[0]));
c4e390
   pattern[l] = '\\';
c4e390
   pattern[l + 1] = '*';
c4e390
diff --git a/grub-core/osdep/windows/init.c b/grub-core/osdep/windows/init.c
c4e390
index 98c325c203d..ef7d2807795 100644
c4e390
--- a/grub-core/osdep/windows/init.c
c4e390
+++ b/grub-core/osdep/windows/init.c
c4e390
@@ -161,7 +161,7 @@ grub_util_host_init (int *argc __attribute__ ((unused)),
c4e390
   LPWSTR *targv;
c4e390
 
c4e390
   targv = CommandLineToArgvW (tcmdline, argc);
c4e390
-  *argv = xmalloc ((*argc + 1) * sizeof (argv[0]));
c4e390
+  *argv = xcalloc (*argc + 1, sizeof (argv[0]));
c4e390
 
c4e390
   for (i = 0; i < *argc; i++)
c4e390
     (*argv)[i] = grub_util_tchar_to_utf8 (targv[i]); 
c4e390
diff --git a/grub-core/osdep/windows/platform.c b/grub-core/osdep/windows/platform.c
c4e390
index d217efe1704..9fe999731eb 100644
c4e390
--- a/grub-core/osdep/windows/platform.c
c4e390
+++ b/grub-core/osdep/windows/platform.c
c4e390
@@ -225,8 +225,8 @@ grub_install_register_efi (grub_device_t efidir_grub_dev,
c4e390
     grub_util_error ("%s", _("no EFI routines are available when running in BIOS mode"));
c4e390
 
c4e390
   distrib8_len = grub_strlen (efi_distributor);
c4e390
-  distributor16 = xmalloc ((distrib8_len + 1) * GRUB_MAX_UTF16_PER_UTF8
c4e390
-			   * sizeof (grub_uint16_t));
c4e390
+  distributor16 = xcalloc (distrib8_len + 1,
c4e390
+			   GRUB_MAX_UTF16_PER_UTF8 * sizeof (grub_uint16_t));
c4e390
   distrib16_len = grub_utf8_to_utf16 (distributor16, distrib8_len * GRUB_MAX_UTF16_PER_UTF8,
c4e390
 				      (const grub_uint8_t *) efi_distributor,
c4e390
 				      distrib8_len, 0);
c4e390
diff --git a/grub-core/osdep/windows/relpath.c b/grub-core/osdep/windows/relpath.c
c4e390
index cb0861744ae..478e8ef14d5 100644
c4e390
--- a/grub-core/osdep/windows/relpath.c
c4e390
+++ b/grub-core/osdep/windows/relpath.c
c4e390
@@ -72,7 +72,7 @@ grub_make_system_path_relative_to_its_root (const char *path)
c4e390
       if (dirwindows[0] && dirwindows[1] == ':')
c4e390
 	offset = 2;
c4e390
     }
c4e390
-  ret = xmalloc (sizeof (ret[0]) * (flen - offset + 2));
c4e390
+  ret = xcalloc (flen - offset + 2, sizeof (ret[0]));
c4e390
   if (dirwindows[offset] != '\\'
c4e390
       && dirwindows[offset] != '/'
c4e390
       && dirwindows[offset])
c4e390
diff --git a/grub-core/partmap/gpt.c b/grub-core/partmap/gpt.c
c4e390
index 83bcba77914..5fae4cad059 100644
c4e390
--- a/grub-core/partmap/gpt.c
c4e390
+++ b/grub-core/partmap/gpt.c
c4e390
@@ -199,7 +199,7 @@ gpt_partition_map_embed (struct grub_disk *disk, unsigned int *nsectors,
c4e390
   *nsectors = ctx.len;
c4e390
   if (*nsectors > max_nsectors)
c4e390
     *nsectors = max_nsectors;
c4e390
-  *sectors = grub_malloc (*nsectors * sizeof (**sectors));
c4e390
+  *sectors = grub_calloc (*nsectors, sizeof (**sectors));
c4e390
   if (!*sectors)
c4e390
     return grub_errno;
c4e390
   for (i = 0; i < *nsectors; i++)
c4e390
diff --git a/grub-core/partmap/msdos.c b/grub-core/partmap/msdos.c
c4e390
index 46c406bff1f..d604f5a0e55 100644
c4e390
--- a/grub-core/partmap/msdos.c
c4e390
+++ b/grub-core/partmap/msdos.c
c4e390
@@ -337,7 +337,7 @@ pc_partition_map_embed (struct grub_disk *disk, unsigned int *nsectors,
c4e390
       avail_nsectors = *nsectors;
c4e390
       if (*nsectors > max_nsectors)
c4e390
 	*nsectors = max_nsectors;
c4e390
-      *sectors = grub_malloc (*nsectors * sizeof (**sectors));
c4e390
+      *sectors = grub_calloc (*nsectors, sizeof (**sectors));
c4e390
       if (!*sectors)
c4e390
 	return grub_errno;
c4e390
       for (i = 0; i < *nsectors; i++)
c4e390
diff --git a/grub-core/script/execute.c b/grub-core/script/execute.c
c4e390
index cec9539a47c..043b4c4bb66 100644
c4e390
--- a/grub-core/script/execute.c
c4e390
+++ b/grub-core/script/execute.c
c4e390
@@ -586,7 +586,7 @@ gettext_append (struct grub_script_argv *result, const char *orig_str)
c4e390
   for (iptr = orig_str; *iptr; iptr++)
c4e390
     if (*iptr == '$')
c4e390
       dollar_cnt++;
c4e390
-  ctx.allowed_strings = grub_malloc (sizeof (ctx.allowed_strings[0]) * dollar_cnt);
c4e390
+  ctx.allowed_strings = grub_calloc (dollar_cnt, sizeof (ctx.allowed_strings[0]));
c4e390
 
c4e390
   if (parse_string (orig_str, gettext_save_allow, &ctx, 0))
c4e390
     goto fail;
c4e390
diff --git a/grub-core/tests/fake_input.c b/grub-core/tests/fake_input.c
c4e390
index 2d60852989c..b5eb516be2d 100644
c4e390
--- a/grub-core/tests/fake_input.c
c4e390
+++ b/grub-core/tests/fake_input.c
c4e390
@@ -49,7 +49,7 @@ grub_terminal_input_fake_sequence (int *seq_in, int nseq_in)
c4e390
     saved = grub_term_inputs;
c4e390
   if (seq)
c4e390
     grub_free (seq);
c4e390
-  seq = grub_malloc (nseq_in * sizeof (seq[0]));
c4e390
+  seq = grub_calloc (nseq_in, sizeof (seq[0]));
c4e390
   if (!seq)
c4e390
     return;
c4e390
 
c4e390
diff --git a/grub-core/tests/video_checksum.c b/grub-core/tests/video_checksum.c
c4e390
index 74d5b65e5c7..44d0810698a 100644
c4e390
--- a/grub-core/tests/video_checksum.c
c4e390
+++ b/grub-core/tests/video_checksum.c
c4e390
@@ -336,7 +336,7 @@ grub_video_capture_write_bmp (const char *fname,
c4e390
     {
c4e390
     case 4:
c4e390
       {
c4e390
-	grub_uint8_t *buffer = xmalloc (mode_info->width * 3);
c4e390
+	grub_uint8_t *buffer = xcalloc (3, mode_info->width);
c4e390
 	grub_uint32_t rmask = ((1 << mode_info->red_mask_size) - 1);
c4e390
 	grub_uint32_t gmask = ((1 << mode_info->green_mask_size) - 1);
c4e390
 	grub_uint32_t bmask = ((1 << mode_info->blue_mask_size) - 1);
c4e390
@@ -367,7 +367,7 @@ grub_video_capture_write_bmp (const char *fname,
c4e390
       }
c4e390
     case 3:
c4e390
       {
c4e390
-	grub_uint8_t *buffer = xmalloc (mode_info->width * 3);
c4e390
+	grub_uint8_t *buffer = xcalloc (3, mode_info->width);
c4e390
 	grub_uint32_t rmask = ((1 << mode_info->red_mask_size) - 1);
c4e390
 	grub_uint32_t gmask = ((1 << mode_info->green_mask_size) - 1);
c4e390
 	grub_uint32_t bmask = ((1 << mode_info->blue_mask_size) - 1);
c4e390
@@ -407,7 +407,7 @@ grub_video_capture_write_bmp (const char *fname,
c4e390
       }
c4e390
     case 2:
c4e390
       {
c4e390
-	grub_uint8_t *buffer = xmalloc (mode_info->width * 3);
c4e390
+	grub_uint8_t *buffer = xcalloc (3, mode_info->width);
c4e390
 	grub_uint16_t rmask = ((1 << mode_info->red_mask_size) - 1);
c4e390
 	grub_uint16_t gmask = ((1 << mode_info->green_mask_size) - 1);
c4e390
 	grub_uint16_t bmask = ((1 << mode_info->blue_mask_size) - 1);
c4e390
diff --git a/grub-core/video/capture.c b/grub-core/video/capture.c
c4e390
index 4f83c744116..4d3195e017b 100644
c4e390
--- a/grub-core/video/capture.c
c4e390
+++ b/grub-core/video/capture.c
c4e390
@@ -89,7 +89,7 @@ grub_video_capture_start (const struct grub_video_mode_info *mode_info,
c4e390
   framebuffer.mode_info = *mode_info;
c4e390
   framebuffer.mode_info.blit_format = grub_video_get_blit_format (&framebuffer.mode_info);
c4e390
 
c4e390
-  framebuffer.ptr = grub_malloc (framebuffer.mode_info.height * framebuffer.mode_info.pitch);
c4e390
+  framebuffer.ptr = grub_calloc (framebuffer.mode_info.height, framebuffer.mode_info.pitch);
c4e390
   if (!framebuffer.ptr)
c4e390
     return grub_errno;
c4e390
   
c4e390
diff --git a/grub-core/video/emu/sdl.c b/grub-core/video/emu/sdl.c
c4e390
index a2f639f66de..0ebab6f57dd 100644
c4e390
--- a/grub-core/video/emu/sdl.c
c4e390
+++ b/grub-core/video/emu/sdl.c
c4e390
@@ -172,7 +172,7 @@ grub_video_sdl_set_palette (unsigned int start, unsigned int count,
c4e390
       if (start + count > mode_info.number_of_colors)
c4e390
 	count = mode_info.number_of_colors - start;
c4e390
 
c4e390
-      tmp = grub_malloc (count * sizeof (tmp[0]));
c4e390
+      tmp = grub_calloc (count, sizeof (tmp[0]));
c4e390
       for (i = 0; i < count; i++)
c4e390
 	{
c4e390
 	  tmp[i].r = palette_data[i].r;
c4e390
diff --git a/grub-core/video/i386/pc/vga.c b/grub-core/video/i386/pc/vga.c
c4e390
index 01f47112d37..b2f776c997b 100644
c4e390
--- a/grub-core/video/i386/pc/vga.c
c4e390
+++ b/grub-core/video/i386/pc/vga.c
c4e390
@@ -127,7 +127,7 @@ grub_video_vga_setup (unsigned int width, unsigned int height,
c4e390
 
c4e390
   vga_height = height ? : 480;
c4e390
 
c4e390
-  framebuffer.temporary_buffer = grub_malloc (vga_height * VGA_WIDTH);
c4e390
+  framebuffer.temporary_buffer = grub_calloc (vga_height, VGA_WIDTH);
c4e390
   framebuffer.front_page = 0;
c4e390
   framebuffer.back_page = 0;
c4e390
   if (!framebuffer.temporary_buffer)
c4e390
diff --git a/grub-core/video/readers/png.c b/grub-core/video/readers/png.c
c4e390
index 1f03f88d396..0a1c6584dd3 100644
c4e390
--- a/grub-core/video/readers/png.c
c4e390
+++ b/grub-core/video/readers/png.c
c4e390
@@ -309,7 +309,7 @@ grub_png_decode_image_header (struct grub_png_data *data)
c4e390
   if (data->is_16bit || data->is_gray || data->is_palette)
c4e390
 #endif
c4e390
     {
c4e390
-      data->image_data = grub_malloc (data->image_height * data->row_bytes);
c4e390
+      data->image_data = grub_calloc (data->image_height, data->row_bytes);
c4e390
       if (grub_errno)
c4e390
         return grub_errno;
c4e390
 
c4e390
diff --git a/util/getroot.c b/util/getroot.c
c4e390
index e70061099b3..f523c63b933 100644
c4e390
--- a/util/getroot.c
c4e390
+++ b/util/getroot.c
c4e390
@@ -218,7 +218,7 @@ make_device_name (const char *drive)
c4e390
   char *ret, *ptr;
c4e390
   const char *iptr;
c4e390
 
c4e390
-  ret = xmalloc (strlen (drive) * 2);
c4e390
+  ret = xcalloc (2, strlen (drive));
c4e390
   ptr = ret;
c4e390
   for (iptr = drive; *iptr; iptr++)
c4e390
     {
c4e390
diff --git a/util/grub-file.c b/util/grub-file.c
c4e390
index 9989dfe7b6b..6f4ca6c2091 100644
c4e390
--- a/util/grub-file.c
c4e390
+++ b/util/grub-file.c
c4e390
@@ -54,7 +54,7 @@ main (int argc, char *argv[])
c4e390
 
c4e390
   grub_util_host_init (&argc, &argv);
c4e390
 
c4e390
-  argv2 = xmalloc (argc * sizeof (argv2[0]));
c4e390
+  argv2 = xcalloc (argc, sizeof (argv2[0]));
c4e390
 
c4e390
   if (argc == 2 && strcmp (argv[1], "--version") == 0)
c4e390
     {
c4e390
diff --git a/util/grub-fstest.c b/util/grub-fstest.c
c4e390
index 31af2a7ad9c..77f12ca93ce 100644
c4e390
--- a/util/grub-fstest.c
c4e390
+++ b/util/grub-fstest.c
c4e390
@@ -734,7 +734,7 @@ main (int argc, char *argv[])
c4e390
 
c4e390
   grub_util_host_init (&argc, &argv);
c4e390
 
c4e390
-  args = xmalloc (argc * sizeof (args[0]));
c4e390
+  args = xcalloc (argc, sizeof (args[0]));
c4e390
 
c4e390
   argp_parse (&argp, argc, argv, 0, 0, 0);
c4e390
 
c4e390
diff --git a/util/grub-install-common.c b/util/grub-install-common.c
c4e390
index c8bedcb2e59..d49a93d4740 100644
c4e390
--- a/util/grub-install-common.c
c4e390
+++ b/util/grub-install-common.c
c4e390
@@ -280,7 +280,7 @@ handle_install_list (struct install_list *il, const char *val,
c4e390
       il->n_entries++;
c4e390
     }
c4e390
   il->n_alloc = il->n_entries + 1;
c4e390
-  il->entries = xmalloc (il->n_alloc * sizeof (il->entries[0]));
c4e390
+  il->entries = xcalloc (il->n_alloc, sizeof (il->entries[0]));
c4e390
   ptr = val;
c4e390
   for (ce = il->entries; ; ce++)
c4e390
     {
c4e390
diff --git a/util/grub-install.c b/util/grub-install.c
c4e390
index 947a2d2ddf5..28132b66bea 100644
c4e390
--- a/util/grub-install.c
c4e390
+++ b/util/grub-install.c
c4e390
@@ -624,6 +624,8 @@ device_map_check_duplicates (const char *dev_map)
c4e390
   if (! fp)
c4e390
     return;
c4e390
 
c4e390
+  d = xcalloc (alloced, sizeof (d[0]));
c4e390
+
c4e390
   while (fgets (buf, sizeof (buf), fp))
c4e390
     {
c4e390
       char *p = buf;
c4e390
@@ -1224,7 +1226,7 @@ main (int argc, char *argv[])
c4e390
       ndev++;
c4e390
     }
c4e390
 
c4e390
-  grub_drives = xmalloc (sizeof (grub_drives[0]) * (ndev + 1)); 
c4e390
+  grub_drives = xcalloc (ndev + 1, sizeof (grub_drives[0]));
c4e390
 
c4e390
   for (curdev = grub_devices, curdrive = grub_drives; *curdev; curdev++,
c4e390
        curdrive++)
c4e390
diff --git a/util/grub-mkimagexx.c b/util/grub-mkimagexx.c
c4e390
index d1bc95e350d..b03a6089905 100644
c4e390
--- a/util/grub-mkimagexx.c
c4e390
+++ b/util/grub-mkimagexx.c
c4e390
@@ -1375,7 +1375,7 @@ SUFFIX (locate_sections) (const char *kernel_path,
c4e390
   if (image_target->elf_target == EM_AARCH64)
c4e390
     *all_align = 4096;
c4e390
 
c4e390
-  section_addresses = xmalloc (sizeof (*section_addresses) * num_sections);
c4e390
+  section_addresses = xcalloc (num_sections, sizeof (*section_addresses));
c4e390
   memset (section_addresses, 0, sizeof (*section_addresses) * num_sections);
c4e390
 
c4e390
   current_address = 0;
c4e390
@@ -1512,7 +1512,7 @@ SUFFIX (load_image) (const char *kernel_path, size_t *exec_size,
c4e390
 						exec_size, kernel_sz, align,
c4e390
 						image_target);
c4e390
 
c4e390
-  section_vaddresses = xmalloc (sizeof (*section_addresses) * num_sections);
c4e390
+  section_vaddresses = xcalloc (num_sections, sizeof (*section_addresses));
c4e390
 
c4e390
   for (i = 0; i < num_sections; i++)
c4e390
     section_vaddresses[i] = section_addresses[i] + image_target->vaddr_offset;
c4e390
diff --git a/util/grub-mkstandalone.c b/util/grub-mkstandalone.c
c4e390
index 8e2a2b8c27a..1d6edcf3315 100644
c4e390
--- a/util/grub-mkstandalone.c
c4e390
+++ b/util/grub-mkstandalone.c
c4e390
@@ -295,7 +295,7 @@ main (int argc, char *argv[])
c4e390
   grub_util_host_init (&argc, &argv);
c4e390
   grub_util_disable_fd_syncs ();
c4e390
 
c4e390
-  files = xmalloc ((argc + 1) * sizeof (files[0]));
c4e390
+  files = xcalloc (argc + 1, sizeof (files[0]));
c4e390
 
c4e390
   argp_parse (&argp, argc, argv, 0, 0, 0);
c4e390
 
c4e390
diff --git a/util/grub-pe2elf.c b/util/grub-pe2elf.c
c4e390
index f4abf70a3f3..bc326eb91c6 100644
c4e390
--- a/util/grub-pe2elf.c
c4e390
+++ b/util/grub-pe2elf.c
c4e390
@@ -100,9 +100,9 @@ write_section_data (FILE* fp, const char *name, char *image,
c4e390
   char *pe_strtab = (image + pe_chdr->symtab_offset
c4e390
 		     + pe_chdr->num_symbols * sizeof (struct grub_pe32_symbol));
c4e390
 
c4e390
-  section_map = xmalloc ((2 * pe_chdr->num_sections + 5) * sizeof (int));
c4e390
+  section_map = xcalloc (2 * pe_chdr->num_sections + 5, sizeof (int));
c4e390
   section_map[0] = 0;
c4e390
-  shdr = xmalloc ((2 * pe_chdr->num_sections + 5) * sizeof (shdr[0]));
c4e390
+  shdr = xcalloc (2 * pe_chdr->num_sections + 5, sizeof (shdr[0]));
c4e390
   idx = 1;
c4e390
   idx_reloc = pe_chdr->num_sections + 1;
c4e390
 
c4e390
@@ -233,7 +233,7 @@ write_reloc_section (FILE* fp, const char *name, char *image,
c4e390
 
c4e390
       pe_sec = pe_shdr + shdr[i].sh_link;
c4e390
       pe_rel = (struct grub_pe32_reloc *) (image + pe_sec->relocations_offset);
c4e390
-      rel = (elf_reloc_t *) xmalloc (pe_sec->num_relocations * sizeof (elf_reloc_t));
c4e390
+      rel = (elf_reloc_t *) xcalloc (pe_sec->num_relocations, sizeof (elf_reloc_t));
c4e390
       num_rels = 0;
c4e390
       modified = 0;
c4e390
 
c4e390
@@ -365,12 +365,10 @@ write_symbol_table (FILE* fp, const char *name, char *image,
c4e390
   pe_symtab = (struct grub_pe32_symbol *) (image + pe_chdr->symtab_offset);
c4e390
   pe_strtab = (char *) (pe_symtab + pe_chdr->num_symbols);
c4e390
 
c4e390
-  symtab = (Elf_Sym *) xmalloc ((pe_chdr->num_symbols + 1) *
c4e390
-				sizeof (Elf_Sym));
c4e390
-  memset (symtab, 0, (pe_chdr->num_symbols + 1) * sizeof (Elf_Sym));
c4e390
+  symtab = (Elf_Sym *) xcalloc (pe_chdr->num_symbols + 1, sizeof (Elf_Sym));
c4e390
   num_syms = 1;
c4e390
 
c4e390
-  symtab_map = (int *) xmalloc (pe_chdr->num_symbols * sizeof (int));
c4e390
+  symtab_map = (int *) xcalloc (pe_chdr->num_symbols, sizeof (int));
c4e390
 
c4e390
   for (i = 0; i < (int) pe_chdr->num_symbols;
c4e390
        i += pe_symtab->num_aux + 1, pe_symtab += pe_symtab->num_aux + 1)
c4e390
diff --git a/util/grub-probe.c b/util/grub-probe.c
c4e390
index ecb7b6bbdf2..731b61df89b 100644
c4e390
--- a/util/grub-probe.c
c4e390
+++ b/util/grub-probe.c
c4e390
@@ -304,8 +304,8 @@ probe (const char *path, char **device_names, char delim)
c4e390
       grub_util_pull_device (*curdev);
c4e390
       ndev++;
c4e390
     }
c4e390
-  
c4e390
-  drives_names = xmalloc (sizeof (drives_names[0]) * (ndev + 1)); 
c4e390
+
c4e390
+  drives_names = xcalloc (ndev + 1, sizeof (drives_names[0]));
c4e390
 
c4e390
   for (curdev = device_names, curdrive = drives_names; *curdev; curdev++,
c4e390
        curdrive++)
c4e390
diff --git a/include/grub/unicode.h b/include/grub/unicode.h
c4e390
index a0403e91f9a..4de986a8576 100644
c4e390
--- a/include/grub/unicode.h
c4e390
+++ b/include/grub/unicode.h
c4e390
@@ -293,7 +293,7 @@ grub_unicode_glyph_dup (const struct grub_unicode_glyph *in)
c4e390
   grub_memcpy (out, in, sizeof (*in));
c4e390
   if (in->ncomb > ARRAY_SIZE (out->combining_inline))
c4e390
     {
c4e390
-      out->combining_ptr = grub_malloc (in->ncomb * sizeof (out->combining_ptr[0]));
c4e390
+      out->combining_ptr = grub_calloc (in->ncomb, sizeof (out->combining_ptr[0]));
c4e390
       if (!out->combining_ptr)
c4e390
 	{
c4e390
 	  grub_free (out);
c4e390
@@ -315,7 +315,7 @@ grub_unicode_set_glyph (struct grub_unicode_glyph *out,
c4e390
   grub_memcpy (out, in, sizeof (*in));
c4e390
   if (in->ncomb > ARRAY_SIZE (out->combining_inline))
c4e390
     {
c4e390
-      out->combining_ptr = grub_malloc (in->ncomb * sizeof (out->combining_ptr[0]));
c4e390
+      out->combining_ptr = grub_calloc (in->ncomb, sizeof (out->combining_ptr[0]));
c4e390
       if (!out->combining_ptr)
c4e390
 	return;
c4e390
       grub_memcpy (out->combining_ptr, in->combining_ptr,