antirez / antirez/kilo

Enhance memory safety and buffer initialization for stability

Offen
#100 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
C
Sterne
9.1k
Forks
995
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### Describe

I found potential memory safety and stability issues in the kilo codebase:

- **CWE-476 (NULL Pointer Dereference)**:

In `editorUpdateSyntax`, `editorRowAppendString`, and `editorOpen`, memory allocation results (via `realloc` or `malloc`) are not properly checked for `NULL`.

This could lead to memory leaks or crashes if an allocation fails.

- **CWE-457 (Use of Uninitialized Variable)**:

In `getCursorPosition`, the buffer `buf` is not explicitly initialized, which could result in undefined behavior.

### Expected behavior

- Memory allocation failures (e.g., `realloc`, `malloc`) should be properly handled and should not overwrite original pointers.
- Buffers should be initialized before use to avoid undefined behavior.

### Actual behavior

- In multiple functions, the return values of `realloc` or `malloc` are not checked before dereferencing.
- In `getCursorPosition`, `buf` may contain uninitialized data before valid input is read.

### How to Reproduce

- Simulate low-memory conditions (e.g., `ulimit -v 10000` on Linux) and observe crashes or instability.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.