Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c

From: Date: Tue, 29 Mar 2016 07:13:45 +0000
Subject: Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-91513@lists.php.net to get a copy of this message
Hi Stas, On Mon, Mar 28, 2016 at 5:22 PM, Stanislav Malyshev <stas@php.net> wrote: > @@ -1501,7 +1501,7 @@ mbfl_strcut( > if (encoding->flag & (MBFL_ENCTYPE_WCS2BE | MBFL_ENCTYPE_WCS2LE)) { > from &= -2; > > - if (from + length >= string->len) { > + if (length >= string->len - from) { > length = string->len - from; > } > > @@ -1510,14 +1510,14 @@ mbfl_strcut( > } else if (encoding->flag & (MBFL_ENCTYPE_WCS4BE | MBFL_ENCTYPE_WCS4LE)) > { > from &= -4; > > - if (from + length >= string->len) { > + if (length >= string->len - from) { > length = string->len - from; > } > > start = string->val + from; > end = start + (length & -4); > } else if ((encoding->flag & MBFL_ENCTYPE_SBCS)) { > - if (from + length >= string->len) { > + if (length >= string->len - from) { > length = string->len - from; > } > > @@ -1539,7 +1539,7 @@ mbfl_strcut( > start = p; > > /* search end position */ > - if ((start - string->val) + length >= (int)string->len) { > + if (length >= (int)string->len - (start - string->val)) { > end = string->val + string->len; > } else { > for (q = p + length; p < q; p += (m = mbtab[*p])); It seems effective changes are these excluding WS changes. These changes are X + A >= B to A >= B - X Does this really fix issue? My first impression of this bug's cause of signed vs. unsigned int difference. i.e. Mbstring uses unsigned int for string length. IIRC. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.cvs (#91513) next »