Pārlūkot izejas kodu

leveldb: Check slice length in Footer::DecodeFrom()

Without this check decoding the footer in Table::Open() can read
uninitialized bytes from a buffer allocated on the stack if the file
was unexpectedly short.

In practice this is probably fine since this function validates a magic
number but MSan complains about branching on uninitialized data.

PiperOrigin-RevId: 525271012
pull/1/head
leveldb Team pirms 1 gada
revīziju iesūtīja Austin Sullivan
vecāks
revīzija
068d5ee1a3
1 mainītis faili ar 4 papildinājumiem un 0 dzēšanām
  1. +4
    -0
      table/format.cc

+ 4
- 0
table/format.cc Parādīt failu

@ -41,6 +41,10 @@ void Footer::EncodeTo(std::string* dst) const {
}
Status Footer::DecodeFrom(Slice* input) {
if (input->size() < kEncodedLength) {
return Status::Corruption("not an sstable (footer too short)");
}
const char* magic_ptr = input->data() + kEncodedLength - 8;
const uint32_t magic_lo = DecodeFixed32(magic_ptr);
const uint32_t magic_hi = DecodeFixed32(magic_ptr + 4);

Notiek ielāde…
Atcelt
Saglabāt