Skip to content

JIT: (bug) bounds check removed in loop with wrapping induction variable #134451

Description

@EgorBo

Range check removes the bounds check on a[j] in a loop where j can become negative after x wraps around, leading to an out-of-bounds read.

Minimal Repro

using System;
using System.Runtime.CompilerServices;

public class Program
{
    public static void Main()
    {
        try
        {
            Console.WriteLine(Test(new int[101], true));
        }
        catch (Exception e)
        {
            Console.WriteLine(e.GetType().Name);
        }
    }

    [MethodImpl(MethodImplOptions.NoInlining | MethodImplOptions.AggressiveOptimization)]
    static int Test(int[] a, bool flag)
    {
        int j = 0, x = 0, sum = 0;
        if (a.Length != 101)
            return 0;
        while (j < 101)
        {
            if (flag)
                sum += a[j];
            x++;
            if (x >= -100 && x <= 10)
                j += x;
        }
        return sum;
    }
}

(Takes ~5 seconds since x has to wrap around once.)

Expected

IndexOutOfRangeException (j reaches 55, then after x wraps to -100, j becomes -45). Same as with DOTNET_JitMinOpts=1 or DOTNET_JitDoRangeAnalysis=0.

Actual

UB

Regression?

Yes, regressed in .NET 10: .NET 8 and 9 are correct; .NET 10, 11 RC2 and main are affected (win-x64).

Notes

In DoesVarDefOverflow(x), Merge(<Dependent, 100>, [-100, 10]) equals the top-level range of j, so it returns "no overflow" without inspecting the def x = x + 1.
Widen then treats j += x as monotonic and gives j the range [0, 100]. The shortcut compares against the top-level range instead of x's own contribution, and is also unsound when the lower limit is Dependent.

Activity

  1. added this to the 12.0.0 milestone on Sep 22, 2026
  2. added
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    on Sep 22, 2026
  3. dotnet-policy-service commented on Sep 22, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  4. self-assigned this
    on Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions