Actions
Bug #22387
openstr_shared_replace incorrectly recalculates termlen
Bug #22387:
str_shared_replace incorrectly recalculates termlen
Description
This ruby snippet crashes under ASan with a heap-buffer-overflow
s = ("\u{30AF}" * 7).encode("UTF-16LE").b
s.force_encoding("UTF-16LE")
s.encode!("UTF-8") # 21 bytes in a 22-byte malloc, capa now claims 22
s << "x" # fits, per capa, then NUL terminator written at [22]
str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy.
We can just switch that to rb_enc_raw_set to fix.
Actions