Skip to content

fix(cutile-rs): reject overflowing section lengths and varints in bytecode decoder - #1448

Open
dawnop wants to merge 1 commit into
NVIDIA:mainfrom
dawnop:fix/cutile-bytecode-decoder-overflow
Open

dawnop wants to merge 1 commit into
NVIDIA:mainfrom
dawnop:fix/cutile-bytecode-decoder-overflow

Conversation

@dawnop

@dawnop dawnop commented Oct 8, 2026

Copy link
Copy Markdown

Transplanted from NVlabs/cutile-rs#322, which was closed when the repository moved here. Closes #1443.

Fixes two input-validation bugs in cutile-ir's bytecode Reader:

  • read_bytes checked self.pos + n > len, which overflows for a huge
    section length. Debug builds panic on the overflow. In release builds the
    sum wraps, the check passes, and the slice then panics. It now checks
    n > self.remaining().
  • read_varint accepted a 10th byte with payload > 1. The extra high bits
    were shifted out, so the value was silently truncated. For example, a
    section length could wrap to 1 and be accepted. It now rejects a 10th byte
    other than 0x00/0x01.

Tests:

  • decode_rejection.rs: reject_section_length_overflow and
    reject_section_length_varint_overflow both fail on main and pass with
    this change.
  • decoder.rs: varint_u64_boundaries round-trips 0, 127, 128, 2^63 and
    u64::MAX.

cargo test -p cutile-ir, cargo fmt --check and cargo clippy --all-targets -- -D warnings pass under cutile-rs/ with the pinned 1.98.0 toolchain. The change is identical to #322, where bash scripts/run_all.sh passed locally.

…ecode decoder

read_bytes checked `pos + n > len`, which overflows for a huge section
length; check `n > remaining()` instead. read_varint accepted a 10th byte
with payload > 1 and silently truncated the value; reject it.

Transplanted from NVlabs/cutile-rs#322.

Signed-off-by: dawnop <dawnlulucifer@gmail.com>
@dawnop
dawnop requested a review from elibol as a code owner October 8, 2026 04:47
@copy-pr-bot

copy-pr-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: reject overflowing section lengths and varints in bytecode decoder

1 participant