Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c

From: Date: Tue, 29 Mar 2016 07:24:58 +0000
Subject: Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c
References: 1 2 3  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-91516@lists.php.net to get a copy of this message
Hi Stas, On Tue, Mar 29, 2016 at 4:16 PM, Stanislav Malyshev <smalyshev@gmail.com> wrote: >> It seems effective changes are these excluding WS changes. >> >> These changes are >> >> X + A >= B >> to >> A >= B - X >> >> Does this really fix issue? > > I think it does. Unless you can show me wrong :) > >> My first impression of this bug's cause of signed vs. unsigned int difference. >> i.e. Mbstring uses unsigned int for string length. IIRC. > > Not sure what you mean. The issue was that X+A was overflowing since A > was very big, and thus even though A was too big X+A >= B condition did > not check. If overflow is the problem - if ((start - string->val) + length >= (int)string->len) { + if (length >= (int)string->len - (start - string->val)) { end = string->val + string->len; This end = string->val + string->len; could be problem, perhaps. It seems the fix is incomplete or missing some thing. I'm looking diff only, so I could be wrong though. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.cvs (#91516) next »