antirez / antirez/kilo

Enhance memory safety and buffer initialization for stability

Aperta
#100 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
C
Stelle
9.1k
Fork
995
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Describe

I found potential memory safety and stability issues in the kilo codebase:

- **CWE-476 (NULL Pointer Dereference)**:

In `editorUpdateSyntax`, `editorRowAppendString`, and `editorOpen`, memory allocation results (via `realloc` or `malloc`) are not properly checked for `NULL`.

This could lead to memory leaks or crashes if an allocation fails.

- **CWE-457 (Use of Uninitialized Variable)**:

In `getCursorPosition`, the buffer `buf` is not explicitly initialized, which could result in undefined behavior.

### Expected behavior

- Memory allocation failures (e.g., `realloc`, `malloc`) should be properly handled and should not overwrite original pointers.
- Buffers should be initialized before use to avoid undefined behavior.

### Actual behavior

- In multiple functions, the return values of `realloc` or `malloc` are not checked before dereferencing.
- In `getCursorPosition`, `buf` may contain uninitialized data before valid input is read.

### How to Reproduce

- Simulate low-memory conditions (e.g., `ulimit -v 10000` on Linux) and observe crashes or instability.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.