Skip to content

Commit fecc4e9

Browse files
schuayv8-scoped@luci-project-accounts.iam.gserviceaccount.com
authored andcommitted
[snapshot] Use checked_cast for SnapshotData size
`SnapshotData::SnapshotData(const Serializer*)` computes its buffer size as `kHeaderSize + static_cast<uint32_t>(payload->size())`. This wraps or truncates when the payload size is in [2^32-8, 2^32-1] or above 2^32, causing `AllocateData` to under-allocate. The `memset` of the header plus the `CopyBytes` of the payload will then write past the end of the buffer. This commit prevents the potential heap buffer overflow by using `base::checked_cast<uint32_t>` for the calculation which handles wrapping securely. This mirrors commit d5bd183 which fixed the identical expression in `SerializedCodeData::SerializedCodeData`. Bug: 568626532 Change-Id: I22d56ddf02969f1cbb17775abfd27b61a1bc81cf Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8495896 Commit-Queue: Jakob Linke <jgruber@chromium.org> Reviewed-by: Arash Kazemi <arashk@chromium.org> Reviewed-by: Jakob Linke <jgruber@chromium.org> Cr-Commit-Position: refs/heads/main@{#110263}
1 parent 670996f commit fecc4e9

1 file changed

Lines changed: 2 additions & 4 deletions

File tree

‎src/snapshot/snapshot-data.cc‎

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,7 @@
44

55
#include "src/snapshot/snapshot-data.h"
66

7-
#include <limits>
8-
7+
#include "src/base/numerics/safe_conversions.h"
98
#include "src/common/assert-scope.h"
109
#include "src/snapshot/serializer.h"
1110

@@ -27,7 +26,7 @@ SnapshotData::SnapshotData(const Serializer* serializer) {
2726
const std::vector<uint8_t>* payload = serializer->Payload();
2827

2928
// Calculate sizes.
30-
uint32_t size = kHeaderSize + static_cast<uint32_t>(payload->size());
29+
uint32_t size = base::checked_cast<uint32_t>(payload->size() + kHeaderSize);
3130

3231
// Allocate backing store and create result data.
3332
AllocateData(size);
@@ -37,7 +36,6 @@ SnapshotData::SnapshotData(const Serializer* serializer) {
3736

3837
// Set header values.
3938
SetMagicNumber();
40-
CHECK_LE(payload->size(), std::numeric_limits<uint32_t>::max());
4139
SetHeaderValue(kPayloadLengthOffset, static_cast<uint32_t>(payload->size()));
4240

4341
// Copy serialized data.

0 commit comments

Comments
 (0)