mirror of
https://github.com/google/flatbuffers.git
synced 2026-06-01 19:58:15 +00:00
[Swift] Fix verifier accepting truncated scalar vectors (OOB read/write, RCE) (#9081)
This commit is contained in:
@@ -56,8 +56,15 @@ extension Verifiable {
|
||||
let len: UOffset = try verifier.getValue(at: position)
|
||||
let intLen = Int(len)
|
||||
let start = Int(clamping: (position &+ MemoryLayout<Int32>.size).magnitude)
|
||||
let byteCount = intLen.multipliedReportingOverflow(
|
||||
by: MemoryLayout<T>.size)
|
||||
guard !byteCount.overflow else {
|
||||
throw FlatbuffersErrors.outOfBounds(
|
||||
position: UInt.max,
|
||||
end: verifier.capacity)
|
||||
}
|
||||
try verifier.isAligned(position: start, type: type.self)
|
||||
try verifier.rangeInBuffer(position: start, size: intLen)
|
||||
try verifier.rangeInBuffer(position: start, size: byteCount.partialValue)
|
||||
return (start, intLen)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user