Bug#1114078: cfortran: Patch to fix FTBFS under GCC 15 (C23) and heap buffer overflow under _FORTIFY_SOURCE=3

Viktor Pashaiev w.paszajew at gmail.com
Sat Oct 3 09:46:30 BST 2026


Package: cfortran
Followup-For: Bug #1114078
User: w.paszajew at gmail.com
Usertags: patch

Dear Maintainers,

In Ubuntu stonking (and Debian sid with GCC 15), cfortran fails to build from source due to C23 prototype semantics and a heap buffer overflow in tests under _FORTIFY_SOURCE=3:

1. GCC 15 defaults to C23 where empty parameter lists in prototypes mean strictly 0 arguments. The internal testsuite in eg/ exercises legacy Fortran/C prototypes and function pointer casts into qsort (__compar_fn_t), resulting in:
   e2/e2.c:10:28: error: too many arguments to function 'easy_'; expected 0, have 2
   q/q.c:15: error: passing 'int (*)(void)' to parameter of type '__compar_fn_t'

Setting 'export DEB_CFLAGS_MAINT_APPEND = -std=gnu17' in debian/rules restores GNU17 semantics for building and running the testsuite.

2. In eg/fstr/fstr.c, Pstr allocates malloc(ls > lsave ? ls : lsave) without space for the terminating NUL byte. When strcpy writes lsave+1 bytes, it triggers buffer overflow termination under _FORTIFY_SOURCE=3. Allocating + 1 byte fixes the crash. (Also submitted upstream as PR #3: https://github.com/bastien-roucaries/cfortran/pull/3).

Attached below is the patch against cfortran 20210827-1.1. With this patch, all 41 testsuites pass and the package builds cleanly under GCC 15.

Thank you,
Viktor Pashaiev <w.paszajew at gmail.com>

--- a/debian/rules
+++ b/debian/rules
@@ -4,6 +4,7 @@
 
 # Uncomment this to turn on verbose mode.
 export DH_VERBOSE=1
+export DEB_CFLAGS_MAINT_APPEND = -std=gnu17
 
 %:
 	dh $@ --with autoreconf

--- a/eg/fstr/fstr.c
+++ b/eg/fstr/fstr.c
@@ -16,7 +16,7 @@
 if (!s || !save) { save=s; return; }
 ls    = strlen(s   );
 lsave = strlen(save);
-temp = (char *)malloc(ls>lsave?ls:lsave);
+temp = (char *)malloc((ls>lsave?ls:lsave) + 1);
 /* Switch contents of argument with contents of saved string. */
 strcpy(temp,save);
 strcpy(save,s   );



More information about the debian-science-maintainers mailing list