diff --git a/roaring/fuzz_test.go b/roaring/fuzz_test.go index 69362d947..abcac1c0b 100644 --- a/roaring/fuzz_test.go +++ b/roaring/fuzz_test.go @@ -23,15 +23,40 @@ func TestUnmarshalBinary(t *testing.T) { cr []byte expected string } { - { - cr : []byte(":0\x000\x01\x00\x00\x000000"), //":000000" - expected : "reading roaring header: malformed bitmap, key-cardinality slice overruns buffer at 12", - }, - { + { // Checks for int overflow cr : []byte("<0\x000\x00\x00\x00\x00000000000000" + "0"), //"<000000000000000" expected : "unmarshaling as pilosa roaring: Maximum operation size exceeded", }, + { // Checks for the zero containers situation + cr : []byte(":0\x000\x01\x00\x00\x000000"), //":000000" + expected : "reading roaring header: malformed bitmap, key-cardinality slice overruns buffer at 12", + }, + { // The next 5 check for malformed bitmaps + cr : []byte("<0\x0000000000000000000" + + "\x00\x00\xec\x00\x03\x00\x00\x00\xec000"), //"<000000000000000000ÏÏ000" + expected : "unmarshaling as pilosa roaring: malformed bitmap, key-cardinality not provided for 67372036 containers", + }, + { + cr : []byte("<0\x00\x02\x00\x00\x00\\f\x01\xb5\x8d\x009\v\x01\x00\x00\x00\x00" + + "\x00\x00e\x04\x00\x00\x00\x04\xfd\x00\x01\x00"), //"<0\fµç9e˝" + expected : "unmarshaling as pilosa roaring: malformed bitmap, key-cardinality not provided for 128625322 containers", + }, + { + cr : []byte("<0\x00\x02\x00\x00\x00&x.field safe"), //"<0&x.field safe" + expected : "unmarshaling as pilosa roaring: malformed bitmap, key-cardinality not provided for 53127850 containers", + }, + { + cr : []byte("<0\x00\x00\x14\x00\x00\x00\x80\xffp\x05_ 4\x114089" + + "\x00\x00\xff\x000\x00\x02\x00\x00\x00\x00\xff\u007f\x00\x00\x01\x10\x00\x00j" + + "\x02\x00\x00$\x04_\x00\xff\u007f\xff062616163\x00" + //"<0ġp_ 44089ˇ0ˇj$_ˇˇ0626161630ø¸ad$j√" + "0\x00\x02\x00\x01\xbf\x00\x04\x00\xfcad$\x00\x00j\x10\x00\x00\xc3"), + expected : "unmarshaling as pilosa roaring: malformed bitmap, key-cardinality not provided for 1 containers", + }, + { // 0 containers because the container is partially formed, but not fully (ie. 3/12 = 0) + cr : []byte("<0\x00\x02\x03\x00\x00\x00쳫\v\x00d9\v\x00\x009\v"), //<0쳫 d9 9 + expected : "unmarshaling as pilosa roaring: malformed bitmap, key-cardinality not provided for 0 containers", + }, } for _, crash := range confirmedCrashers { diff --git a/roaring/roaring.go b/roaring/roaring.go index d7334be05..985ffa67e 100644 --- a/roaring/roaring.go +++ b/roaring/roaring.go @@ -1095,7 +1095,7 @@ func (b *Bitmap) writeToUnoptimized(w io.Writer) (n int64, err error) { // unmarshalPilosaRoaring treats data as being encoded in Pilosa's 64 bit // roaring format and decodes it into b. func (b *Bitmap) unmarshalPilosaRoaring(data []byte) error { - if len(data) < headerBaseSize { + if len(data) <= headerBaseSize { return errors.New("data too small") } @@ -1113,6 +1113,9 @@ func (b *Bitmap) unmarshalPilosaRoaring(data []byte) error { // Read key count in bytes sizeof(cookie)+sizeof(flag):(sizeof(cookie)+sizeof(uint32)). keyN := binary.LittleEndian.Uint32(data[3+1 : 8]) + if len(data) < headerBaseSize+int(keyN)*12 { + return fmt.Errorf("malformed bitmap, key-cardinality not provided for %d containers", int(keyN)/12) + } headerSize := headerBaseSize b.Containers.Reset()