struct buffer {
size_t size;
char bufferC[50];
};
/* ... */
void func(struct buffer *buf) {
/* assuming sizeof(size_t) is 4, sizeof(size_t)+sizeof(char)*50 equals 54 */
struct buffer *buf_cpy = (struct buffer *)malloc(sizeof(size_t)+(sizeof(char)*50));
if (buf_cpy == NULL) {
/* Handle malloc() error */
}
/*
* with padding, sizeof(struct buffer) may be greater than 54, causing
* some data to be written outside the bounds of the memory allocated
*/
memcpy(buf_cpy, buf, sizeof(struct buffer));
/* ... */
free(buf_cpy);
}
|