Skip to content

sinfl can read beyond the end of input buffer #69

Description

@cdmaczane

This bug was detected using Clang address sanitizer on Windows (version shipped with Visual Studio 2026).

The stack where the invalid read was detected was:
sinfl_read64
sinfl_refill
sinfl_decompress
sinflate

The fix was to over-allocate the buffer size to be a multiple of 8. I'm guessing this isn't normally a problem because most allocators will return blocks of multiples of 8 on 64 bit systems. In my case I was using a custom scratch allocator that poisons all leftover space that wasn't part of the initially requested size. From what I can tell, the leftover bytes do not need to be zeroed. Could you confirm this?

I'm not sure that the fix is to change reading 8 bytes at a time, which would affect performance. Perhaps just a note at the top of the file?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions