Repository navigation
Commit 92dd66f
committed
Correctly handle wrap around in ring buffer used internally to buffer application data
Motivation:
We didn't correctly handle the case of the ring buffer wraping around and so could up casting an negative value to size_t which would result in producting a value close to SIZE_MAX that then would be used to memcpy.
This had the result of a heap buffer overflow. The likelyness of this increased if the nonApplicationBufferSize was set to a very low value.
Modifications:
Correctly use modulo to calculate the startIndex.
Result:
No more overflow possible1 parent e28f849 commit 92dd66f
1 file changed
Lines changed: 3 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
196 | 196 | | |
197 | 197 | | |
198 | 198 | | |
199 | | - | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
200 | 202 | | |
201 | 203 | | |
202 | 204 | | |
| |||
0 commit comments