00db10
From f8cef4d07d9641e27629bd3ce2d13f5d702fb251 Mon Sep 17 00:00:00 2001
00db10
From: DJ Delorie <dj@delorie.com>
00db10
Date: Wed, 19 Jul 2017 13:14:34 -0400
00db10
Subject: [PATCH] Fix cast-after-dereference
00db10
00db10
Original code was dereferencing a char*, then casting the value
00db10
to size_t.  Should cast the pointer to size_t* then deference.
00db10
---
00db10
 ChangeLog       | 4 ++++
00db10
 grp/grp-merge.c | 2 +-
00db10
 2 files changed, 5 insertions(+), 1 deletion(-)
00db10
00db10
diff --git a/grp/grp-merge.c b/grp/grp-merge.c
00db10
index 6590e5d..035e7a6 100644
00db10
--- a/grp/grp-merge.c
00db10
+++ b/grp/grp-merge.c
00db10
@@ -137,7 +137,7 @@ __merge_grp (struct group *savedgrp, char *savedbuf, char *savedend,
00db10
 
00db10
   /* Get the count of group members from the last sizeof (size_t) bytes in the
00db10
      mergegrp buffer.  */
00db10
-  savedmemcount = (size_t) *(savedend - sizeof (size_t));
00db10
+  savedmemcount = *(size_t *) (savedend - sizeof (size_t));
00db10
 
00db10
   /* Get the count of new members to add.  */
00db10
   for (memcount = 0; mergegrp->gr_mem[memcount]; memcount++)
00db10
-- 
00db10
1.8.3.1
00db10