Skip to content

Fix value strip underflow - #433

Merged
vstakhov merged 2 commits into
vstakhov:masterfrom
tregua87:fix-value-strip-underflow
Oct 7, 2026
Merged

vstakhov merged 2 commits into
vstakhov:masterfrom
tregua87:fix-value-strip-underflow

Conversation

@tregua87

@tregua87 tregua87 commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Fix #432

tregua87 and others added 2 commits October 7, 2026 13:20
After an unquoted value ucl_parse_value strips trailing whitespace by
walking back from chunk->pos with no lower bound. When the value is empty
and starts the chunk - the parser is in a value state from the previous
chunk, say '[', and the next chunk opens with ',', ';', '}' or a NUL - the
loop reads the byte before the chunk's buffer, a one-byte overread.

Within a single chunk that byte belongs to the same buffer, so only
multi-chunk input exposes it; the outcome ('string value must not be empty')
is the same either way.

Bound the loop by the value start.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W3aXdPKAnVwjiNtZstnmPj

@vstakhov vstakhov left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Reproduced the 1-byte read before the chunk start from #432 on master (ASan heap-buffer-overflow in ucl_parse_value); it's clean on this branch.

@vstakhov
vstakhov merged commit 8880c74 into vstakhov:master Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ucl_parse_value() reads one byte before the chunk when stripping trailing spaces

2 participants