Bug#1114078: cfortran: Patch to fix FTBFS under GCC 15 (C23) and heap buffer overflow under _FORTIFY_SOURCE=3
Viktor Pashaiev
w.paszajew at gmail.com
Sat Oct 3 09:46:30 BST 2026
Package: cfortran
Followup-For: Bug #1114078
User: w.paszajew at gmail.com
Usertags: patch
Dear Maintainers,
In Ubuntu stonking (and Debian sid with GCC 15), cfortran fails to build from source due to C23 prototype semantics and a heap buffer overflow in tests under _FORTIFY_SOURCE=3:
1. GCC 15 defaults to C23 where empty parameter lists in prototypes mean strictly 0 arguments. The internal testsuite in eg/ exercises legacy Fortran/C prototypes and function pointer casts into qsort (__compar_fn_t), resulting in:
e2/e2.c:10:28: error: too many arguments to function 'easy_'; expected 0, have 2
q/q.c:15: error: passing 'int (*)(void)' to parameter of type '__compar_fn_t'
Setting 'export DEB_CFLAGS_MAINT_APPEND = -std=gnu17' in debian/rules restores GNU17 semantics for building and running the testsuite.
2. In eg/fstr/fstr.c, Pstr allocates malloc(ls > lsave ? ls : lsave) without space for the terminating NUL byte. When strcpy writes lsave+1 bytes, it triggers buffer overflow termination under _FORTIFY_SOURCE=3. Allocating + 1 byte fixes the crash. (Also submitted upstream as PR #3: https://github.com/bastien-roucaries/cfortran/pull/3).
Attached below is the patch against cfortran 20210827-1.1. With this patch, all 41 testsuites pass and the package builds cleanly under GCC 15.
Thank you,
Viktor Pashaiev <w.paszajew at gmail.com>
--- a/debian/rules
+++ b/debian/rules
@@ -4,6 +4,7 @@
# Uncomment this to turn on verbose mode.
export DH_VERBOSE=1
+export DEB_CFLAGS_MAINT_APPEND = -std=gnu17
%:
dh $@ --with autoreconf
--- a/eg/fstr/fstr.c
+++ b/eg/fstr/fstr.c
@@ -16,7 +16,7 @@
if (!s || !save) { save=s; return; }
ls = strlen(s );
lsave = strlen(save);
-temp = (char *)malloc(ls>lsave?ls:lsave);
+temp = (char *)malloc((ls>lsave?ls:lsave) + 1);
/* Switch contents of argument with contents of saved string. */
strcpy(temp,save);
strcpy(save,s );
More information about the debian-science-maintainers
mailing list