antirez / antirez/lua-cmsgpack
mp_buf_append and sanitizing realloc
オープン
- 主要言語
- C
- スター
- 383
- フォーク
- 122
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
I noticed mp_buf_append and mp_buf_new are not sanitizing the result to [mp_realloc](https://github.com/antirez/lua-cmsgpack/blob/master/lua_cmsgpack.c#L122).
The Lua documentation states that when the pointer is non-null is must behave like realloc (and in the default case it is: `return realloc(ptr, nsize)`). In turn, when realloc fails the original block is left untouched and NULL is returned, which paths into a memcpy (and likely segmenta.... fau.. or something else entirely dependent on `buf->len`).
While a minor issue, a bit of defensive programming here would not hurt.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。