From 55aa864cac9b740fe6118f207b9ea2544b75387f Mon Sep 17 00:00:00 2001 From: Ashley Svetlik Date: Mon, 24 Jun 2019 12:55:32 -0500 Subject: [PATCH] Fixed malformed offset bug in readOffsets --- roaring/fuzz_test.go | 5 +++++ roaring/roaring.go | 4 ++++ 2 files changed, 9 insertions(+) diff --git a/roaring/fuzz_test.go b/roaring/fuzz_test.go index 2ecb641de..e56d3f0ce 100644 --- a/roaring/fuzz_test.go +++ b/roaring/fuzz_test.go @@ -61,6 +61,11 @@ func TestUnmarshalBinary(t *testing.T) { cr: []byte(";0\x000\v00000"), //";00 00000" expected: "reading offsets from official roaring format: offset incomplete: len=10", }, + { // Checks for incomplete offset in readOffsets + cr: []byte(":0\x000\x03\x00\x00\x00000000000000" + + "\x00"), //:0000000000000 + expected: "reading offsets from official roaring format: offset incomplete: len=1", + }, } for _, crash := range confirmedCrashers { diff --git a/roaring/roaring.go b/roaring/roaring.go index fb004254e..b59900ec1 100644 --- a/roaring/roaring.go +++ b/roaring/roaring.go @@ -4527,6 +4527,10 @@ func readOffsets(b *Bitmap, data []byte, pos int, keyN uint32) error { citer, _ := b.Containers.Iterator(0) for i, buf := 0, data[pos:]; i < int(keyN); i, buf = i+1, buf[4:] { + // Verify the offset is fully formed + if len(buf) < 4 { + return fmt.Errorf("offset incomplete: len=%d", len(buf)) + } offset := binary.LittleEndian.Uint32(buf[0:4]) // Verify the offset is within the bounds of the input data. if int(offset) >= len(data) {