From 06b4a47e81955ea1d33a17010d8b8da7fa532056 Mon Sep 17 00:00:00 2001 From: PGZXB Date: Fri, 25 Sep 2026 21:32:32 +0800 Subject: [PATCH] Fix out-of-bounds write in the jerry-snapshot literals-list parser process_generate() reads the entries of a --load-literals-list-format file into the fixed-size globals magic_string_items[JERRY_LITERAL_LENGTH] and magic_string_lengths[JERRY_LITERAL_LENGTH] (4096 entries). The parse loop increments num_of_lit without bounding it against the array capacity, so the 4097th entry writes past the end of both arrays. Reject a literals-list that would exceed JERRY_LITERAL_LENGTH before writing the entry. Fixes #5293 JerryScript-DCO-1.0-Signed-off-by: PGZXB --- jerry-main/main-snapshot.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/jerry-main/main-snapshot.c b/jerry-main/main-snapshot.c index f6c913fe48..c1c997832a 100644 --- a/jerry-main/main-snapshot.c +++ b/jerry-main/main-snapshot.c @@ -320,6 +320,15 @@ process_generate (cli_state_t *cli_state_p, /**< cli state */ jerry_length_t mstr_size = (jerry_length_t) strtol (sp_buffer_p, &sp_buffer_end_p, 10); if (mstr_size > 0) { + if (num_of_lit >= JERRY_LITERAL_LENGTH) + { + jerry_log (JERRY_LOG_LEVEL_ERROR, + "Error: Too many literals in the list (maximum: %d)\n", + JERRY_LITERAL_LENGTH); + jerry_cleanup (); + return JERRY_STANDALONE_EXIT_CODE_FAIL; + } + magic_string_items[num_of_lit] = (jerry_char_t *) (sp_buffer_end_p + 1); magic_string_lengths[num_of_lit] = mstr_size; num_of_lit++;