Skip to content

bound extensionName compare to VK_MAX_EXTENSION_NAME_SIZE - #2042

Merged
charles-lunarg merged 1 commit into
KhronosGroup:mainfrom
aizu-m:extension-name-compare-bounds
Sep 30, 2026
Merged

charles-lunarg merged 1 commit into
KhronosGroup:mainfrom
aizu-m:extension-name-compare-bounds

Conversation

@aizu-m

@aizu-m aizu-m commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

the extension de-duplication path compares two VkExtensionProperties::extensionName values with an unbounded strcmp, so a driver that returns a name filling all VK_MAX_EXTENSION_NAME_SIZE bytes with no terminator makes the compare read past the field and off the end of the list allocation; strncmp bounds it to the array, matching the check already used for driver extension names in extension_manual.c.

@ci-tester-lunarg

Copy link
Copy Markdown

Author aizu-m not on autobuild list. Waiting for curator authorization before starting CI build.

1 similar comment
@ci-tester-lunarg

Copy link
Copy Markdown

Author aizu-m not on autobuild list. Waiting for curator authorization before starting CI build.

@ci-tester-lunarg

Copy link
Copy Markdown

CI Vulkan-Loader build queued with queue ID 136521.

@ci-tester-lunarg

Copy link
Copy Markdown

CI Vulkan-Loader build # 3785 running.

@ci-tester-lunarg

Copy link
Copy Markdown

CI Vulkan-Loader build # 3785 passed.

@charles-lunarg
charles-lunarg merged commit 4df3ba5 into KhronosGroup:main Sep 30, 2026
51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants