Skip to content

fix out-of-bounds read in antlr3UTF16LA backward surrogate peek - #240

Open
zayeem06 wants to merge 1 commit into
antlr:masterfrom
zayeem06:utf16la-backward-surrogate-bounds
Open

fix out-of-bounds read in antlr3UTF16LA backward surrogate peek#240
zayeem06 wants to merge 1 commit into
antlr:masterfrom
zayeem06:utf16la-backward-surrogate-bounds

Conversation

@zayeem06

Copy link
Copy Markdown

antlr3UTF16LA handles negative (lookbehind) LA by scanning backwards, and when the previous unit is a low surrogate it peeks at *(nextChar-1) to see whether a matching high surrogate precedes it. If that backward scan reaches the start of the buffer the peek reads input->data[-1], two bytes before the allocation; this happens with UTF-16 input whose first code unit is a lone low surrogate followed by a negative LA. The forward branch already bounds the equivalent surrogate peek, so I added the matching lower-bound check before the backward peek. I confirmed the read under AddressSanitizer (heap-buffer-overflow of size 2, two bytes before the buffer) and verified it is gone with the guard in place.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant