Conversation
GeometryReader used per-ring end indices and point offsets taken from the .fgb file to index the xy/z/m coordinate arrays without checking them against the number of coordinates actually stored, so a ring end past the xy count read past the coordinate buffer. Record the coordinate count when xy is read and reject ranges that do not fit before allocating or copying.
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
GeometryReaderinsrc/flatgeobuf/geometryreader.cppbuilds ashapeObjfrom an.fgbfeature's coordinates. For a polygon the per-ring end indices come from the geometry'sends()array in the file, andreadLineObj()used them to walkm_xy(and the parallelz/marrays) without checking them against the number of coordinate pairs actually present inxy(). A ring end index past the coordinate count reads past the buffer;readPoint()had the same unchecked indexing. The flatbuffer is not verified, so those sizes are file-controlled.The reader now records the available coordinate-pair count when
xyis read and rejects any ring range that does not fit it (and anyz/marray shorter than the requested points) before allocating or copying. Keeping the check inreadLineObj/readPointcovers point, line, polygon and the multipoint/multiline/multipolygon variants that all funnel through the same code.What are related issues/pull requests?
Same neighbourhood as #7545, which bounded the property blob; this covers the geometry-decoding side.
AI tool usage
Tasklist
/msautotest(follow steps in Regression Testing)tests/unit/test.cpp: decodes a polygon whose ring end exceeds its coordinate count; fails under ASan before the fix, passes after)