Skip to content

Fix OOB read in Ordinal.EqualsIgnoreCaseUtf8_Scalar / StartsWithIgnoreCaseUtf8_Scalar - #134841

Closed
Mrnikbobjeff wants to merge 2 commits into
dotnet:mainfrom
Mrnikbobjeff:fix/utf8-ordinal-ignorecase-oob
Closed

Mrnikbobjeff wants to merge 2 commits into
dotnet:mainfrom
Mrnikbobjeff:fix/utf8-ordinal-ignorecase-oob

Conversation

@Mrnikbobjeff

Copy link
Copy Markdown

Fixes #134840

The length == 3 tail branch in both scalar functions advanced byteOffset by 2 to compose the third byte into a uint. When the NonAscii fallback was taken, it used the now-stale byteOffset with a length that didn't account for the advance, causing a 2-byte read past both buffers.

Fix: use byteOffset + 2 inline instead of mutating byteOffset.

…tf8_Scalar

The length == 3 tail branch advanced byteOffset by 2 to compose the
third byte, but the NonAscii fallback reused the now-stale byteOffset
with a length computed from range (which doesn't account for the tail
advance). This caused the rune-by-rune fallback to start 2 bytes past
the tail with a length 2 bytes too long, reading past both buffers.

Use an inline offset (byteOffset + 2) instead of mutating byteOffset.

Fixes dotnet#134840
@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Sep 29, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-system-globalization
See info in area-owners.md if you want to be subscribed.

Tests that double.TryParse(ReadOnlySpan<byte>) with a custom
NumberFormatInfo whose infinity symbol is a 3-byte UTF-8 sequence
correctly rejects non-matching inputs regardless of trailing memory
content. Covers both the direct 3-byte tail and the 4-byte-loop +
3-byte-tail path.

Ref dotnet#134840
@EgorBo

EgorBo commented Sep 29, 2026

Copy link
Copy Markdown
Member

Let's see if we can fix it by replacing with safe since this PR doesn't fix all issues there #134857

@MihaZupan

Copy link
Copy Markdown
Member

Thank you. The whole logic for this changed in #134857/#134991, so I think this PR is outdated now.

@MihaZupan MihaZupan closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Globalization community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Ordinal.EqualsIgnoreCaseUtf8_Scalar reads 2 bytes past both buffers when tail is 3 bytes with non-ASCII data

3 participants