Fix OOB read in Ordinal.EqualsIgnoreCaseUtf8_Scalar / StartsWithIgnoreCaseUtf8_Scalar - #134841
Closed
Mrnikbobjeff wants to merge 2 commits into
Closed
Mrnikbobjeff wants to merge 2 commits into
Mrnikbobjeff wants to merge 2 commits into
Conversation
…tf8_Scalar The length == 3 tail branch advanced byteOffset by 2 to compose the third byte, but the NonAscii fallback reused the now-stale byteOffset with a length computed from range (which doesn't account for the tail advance). This caused the rune-by-rune fallback to start 2 bytes past the tail with a length 2 bytes too long, reading past both buffers. Use an inline offset (byteOffset + 2) instead of mutating byteOffset. Fixes dotnet#134840
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @dotnet/area-system-globalization |
Tests that double.TryParse(ReadOnlySpan<byte>) with a custom NumberFormatInfo whose infinity symbol is a 3-byte UTF-8 sequence correctly rejects non-matching inputs regardless of trailing memory content. Covers both the direct 3-byte tail and the 4-byte-loop + 3-byte-tail path. Ref dotnet#134840
Mrnikbobjeff
marked this pull request as ready for review
September 29, 2026 11:28
Member
|
Let's see if we can fix it by replacing with safe since this PR doesn't fix all issues there #134857 |
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #134840
The
length == 3tail branch in both scalar functions advancedbyteOffsetby 2 to compose the third byte into auint. When theNonAsciifallback was taken, it used the now-stalebyteOffsetwith a length that didn't account for the advance, causing a 2-byte read past both buffers.Fix: use
byteOffset + 2inline instead of mutatingbyteOffset.