sushie (Bug Bounty)
- Login: sushie
- Registered on: 10/10/2026
- Last sign in: 10/10/2026
Issues
| open | closed | Total | |
|---|---|---|---|
| Assigned issues | 0 | 0 | 0 |
| Reported issues | 0 | 1 | 1 |
Activity
10/10/2026
-
02:40 PM Ruby Bug #22423: String#initialize(encoding:) stores an inflated capacity and writes past the malloc'd buffer on append (rb_str_init termlen double-adjust)
- A proposed patch was shared by nobu in the HackerOne thread for this issue: it prevents rb_enc_cr_str_exact_copy from copying the old encoding's metadata when the encoding is being changed, and uses rb_enc_raw_set in rb_str_init to avoid...
-
02:37 PM Ruby Bug #22423 (Closed): String#initialize(encoding:) stores an inflated capacity and writes past the malloc'd buffer on append (rb_str_init termlen double-adjust)
- Description
-----------
`String#initialize` with `encoding:` and `capacity:` keywords stores a capacity
that is LARGER than the buffer actually allocated, so later in-place growth
(`<<` / `concat`) writes past the end of the malloc'd...