Project

General

Profile

Bug #22387

Updated by rwstauner (Randy Stauner) about 1 hour ago

This ruby snippet crashes under ASan with a heap-buffer-overflow 

 ```ruby 
 s = ("\u{30AF}" * 7).encode("UTF-16LE").b 
 s.force_encoding("UTF-16LE") 
 s.encode!("UTF-8")     # 21 bytes in a 22-byte malloc, capa now claims 22 
 s << "x"               # fits, per capa, then NUL terminator written at [22] 
 ``` 

 str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy. 

 We can just switch that to rb_enc_raw_set to fix.

Back