Skip to content

Fix buffer overrun on a partial block in the C reference functions - #179

Closed
riha-dev wants to merge 1 commit into
ia0:mainfrom
riha-dev:cref-partial-block
Closed

riha-dev wants to merge 1 commit into
ia0:mainfrom
riha-dev:cref-partial-block

Conversation

@riha-dev

@riha-dev riha-dev commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

encode_seq, encode_par, decode_seq and decode_par only compare len against zero while stepping it by the block size, so a length that is not a whole number of blocks wraps size_t and the loop runs off both buffers (adding a 1- or 2-byte case to the encode_exact table is enough to segfault the test binary); each now rounds len down to whole blocks first, which leaves the inner loop and its generated code untouched.

@ia0

ia0 commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Thanks for the PR but the cmp crate is only used for benchmarks where partial blocks are uninteresting. The benchmarks only use full blocks, so there is no buffer overrun.

@ia0 ia0 closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants