Skip to content

Commit 8906dc2

Browse files
ext/mbstring: assert that mb_wchar_to_uuencode() pointer write is in bounds (#23955)
Add a hardening assertion that when `mb_wchar_to_uuencode()` needs to update the length of the previous line, the location being written to is still part of the same overall output string (i.e. at or after the start of the buffer's `str`'s value pointer, and before the end of the char array).
1 parent a423c90 commit 8906dc2

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

‎ext/mbstring/libmbfl/filters/mbfilter_uuencode.c‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -287,6 +287,9 @@ static void mb_wchar_to_uuencode(uint32_t *in, size_t len, mb_convert_buf *buf,
287287
if (n_cached_bits) {
288288
len_byte -= (n_cached_bits == 2) ? 1 : 2;
289289
}
290+
/* The byte we are writing to must be part of the same buffer */
291+
ZEND_ASSERT(len_byte >= (unsigned char *)ZSTR_VAL(buf->str));
292+
ZEND_ASSERT(len_byte < limit);
290293
*len_byte = MIN(bytes_encoded + len + (n_cached_bits ? (n_cached_bits == 2 ? 1 : 2) : 0), 45) + 32;
291294

292295
if (n_cached_bits) {

0 commit comments

Comments
 (0)