Skip to content

flatgeobuf: bound geometry ring ends to the xy coordinate count - #7645

Open
nvxbug wants to merge 1 commit into
MapServer:mainfrom
nvxbug:fgb-geometry-bounds
Open

nvxbug wants to merge 1 commit into
MapServer:mainfrom
nvxbug:fgb-geometry-bounds

Conversation

@nvxbug

@nvxbug nvxbug commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

GeometryReader in src/flatgeobuf/geometryreader.cpp builds a shapeObj from an .fgb feature's coordinates. For a polygon the per-ring end indices come from the geometry's ends() array in the file, and readLineObj() used them to walk m_xy (and the parallel z/m arrays) without checking them against the number of coordinate pairs actually present in xy(). A ring end index past the coordinate count reads past the buffer; readPoint() had the same unchecked indexing. The flatbuffer is not verified, so those sizes are file-controlled.

The reader now records the available coordinate-pair count when xy is read and rejects any ring range that does not fit it (and any z/m array shorter than the requested points) before allocating or copying. Keeping the check in readLineObj/readPoint covers point, line, polygon and the multipoint/multiline/multipolygon variants that all funnel through the same code.

What are related issues/pull requests?

Same neighbourhood as #7545, which bounded the property blob; this covers the geometry-decoding side.

AI tool usage

Tasklist

  • Make sure code is correctly formatted (cf pre-commit configuration)
  • Add test case(s) in /msautotest (follow steps in Regression Testing)
  • Add a regression test (tests/unit/test.cpp: decodes a polygon whose ring end exceeds its coordinate count; fails under ASan before the fix, passes after)
  • Add documentation
  • Review
  • Adjust for comments
  • All CI builds and checks have passed

GeometryReader used per-ring end indices and point offsets taken from the .fgb file to index the xy/z/m coordinate arrays without checking them against the number of coordinates actually stored, so a ring end past the xy count read past the coordinate buffer. Record the coordinate count when xy is read and reject ranges that do not fit before allocating or copying.
@jmckenna

jmckenna commented Sep 8, 2026

Copy link
Copy Markdown
Member

cc @bjornharrtell

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants