Skip to content

Fix heap buffer overflow in uncompress*Array (truncated output allocation) - #735

Open
iliasabk wants to merge 1 commit into
xerial:mainfrom
iliasabk:fix/uncompress-array-length-alignment
Open

iliasabk wants to merge 1 commit into
xerial:mainfrom
iliasabk:fix/uncompress-array-length-alignment

Conversation

@iliasabk

Copy link
Copy Markdown

Fixes #729.

Root cause. The six typed uncompress{Char,Short,Int,Long,Float,Double}Array methods size the result array by integer-dividing the declared uncompressed byte length by the element size, then pass the undivided length to native rawUncompress. When the declared length is not an exact multiple of the element size, Java under-allocates the array by 1 to elementSize-1 bytes while native code writes the full amount — heap buffer overflow past the array's backing storage (CWE-787).

Fix. Reject a declared uncompressed length that is not a multiple of the target element size with IOException before allocation. Legitimate input (from compress*Array on whole typed elements) always has a multiple-of-element-size length, so valid usage is unaffected.

Note. Distinct from CVE-2023-34453/34454/34455 (shuffle/compress integer overflows), CVE-2023-43642 (chunk-length bound in SnappyInputStream), and the compress bounds check in PR #733 (issue #732).

Disclosure: developed with AI assistance.

The six typed uncompress*Array methods size the result array by
integer-dividing the declared uncompressed byte length by the element
size, then pass the undivided length to native rawUncompress. When the
declared length is not a multiple of the element size, the array is
under-allocated by up to (elementSize - 1) bytes while native writes
the full amount: heap buffer overflow.

Reject non-multiple lengths with IOException before allocation.

Fixes xerial#729
@github-actions github-actions Bot added the bug label Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

snappy-java through 1.1.10.8 Heap Buffer Overflow via uncompress*Array (truncated output allocation)

1 participant