Skip to content

Commit 92dd66f

Browse files
committed
Correctly handle wrap around in ring buffer used internally to buffer application data
Motivation: We didn't correctly handle the case of the ring buffer wraping around and so could up casting an negative value to size_t which would result in producting a value close to SIZE_MAX that then would be used to memcpy. This had the result of a heap buffer overflow. The likelyness of this increased if the nonApplicationBufferSize was set to a very low value. Modifications: Correctly use modulo to calculate the startIndex. Result: No more overflow possible
1 parent e28f849 commit 92dd66f

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

  • openssl-dynamic/src/main/c

‎openssl-dynamic/src/main/c/ssl.c‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -196,7 +196,9 @@ static jint tcn_write_to_bytebuffer(BIO* bio, const char* in, int inl) {
196196
}
197197

198198
writeAmount = TCN_MIN(nonApplicationBufferFreeSpace, (jint) inl) * sizeof(char);
199-
startIndex = bioUserData->nonApplicationBufferOffset + bioUserData->nonApplicationBufferLength;
199+
// use modulo to account for wrap around the ring buffer that buffers data.
200+
startIndex = (bioUserData->nonApplicationBufferOffset + bioUserData->nonApplicationBufferLength)
201+
% bioUserData->nonApplicationBufferSize;
200202
writeChunk = bioUserData->nonApplicationBufferSize - startIndex;
201203

202204
#ifdef NETTY_TCNATIVE_BIO_DEBUG

0 commit comments

Comments
 (0)