Project

General

Profile

Actions

Bug #22387

open

str_shared_replace incorrectly recalculates termlen

Bug #22387: str_shared_replace incorrectly recalculates termlen

Added by rwstauner (Randy Stauner) about 1 hour ago. Updated about 1 hour ago.

Status:
Open
Assignee:
-
Target version:
-
[ruby-core:126871]

Description

This ruby snippet crashes under ASan with a heap-buffer-overflow

s = ("\u{30AF}" * 7).encode("UTF-16LE").b
s.force_encoding("UTF-16LE")
s.encode!("UTF-8")   # 21 bytes in a 22-byte malloc, capa now claims 22
s << "x"             # fits, per capa, then NUL terminator written at [22]

str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy.

We can just switch that to rb_enc_raw_set to fix.

Actions

Also available in: PDF Atom