Commit fecc4e9
[snapshot] Use checked_cast for SnapshotData size
`SnapshotData::SnapshotData(const Serializer*)` computes its buffer size
as `kHeaderSize + static_cast<uint32_t>(payload->size())`. This wraps or
truncates when the payload size is in [2^32-8, 2^32-1] or above 2^32,
causing `AllocateData` to under-allocate. The `memset` of the header
plus the `CopyBytes` of the payload will then write past the end of the
buffer.
This commit prevents the potential heap buffer overflow by using
`base::checked_cast<uint32_t>` for the calculation which handles
wrapping securely. This mirrors commit d5bd183 which fixed the
identical expression in `SerializedCodeData::SerializedCodeData`.
Bug: 568626532
Change-Id: I22d56ddf02969f1cbb17775abfd27b61a1bc81cf
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8495896
Commit-Queue: Jakob Linke <jgruber@chromium.org>
Reviewed-by: Arash Kazemi <arashk@chromium.org>
Reviewed-by: Jakob Linke <jgruber@chromium.org>
Cr-Commit-Position: refs/heads/main@{#110263}1 parent 670996f commit fecc4e9
1 file changed
Lines changed: 2 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
8 | | - | |
| 7 | + | |
9 | 8 | | |
10 | 9 | | |
11 | 10 | | |
| |||
27 | 26 | | |
28 | 27 | | |
29 | 28 | | |
30 | | - | |
| 29 | + | |
31 | 30 | | |
32 | 31 | | |
33 | 32 | | |
| |||
37 | 36 | | |
38 | 37 | | |
39 | 38 | | |
40 | | - | |
41 | 39 | | |
42 | 40 | | |
43 | 41 | | |
| |||
0 commit comments