Buffer::Printf: fix OOB stack read on vsnprintf truncation

When vsnprintf's return value (the would-have-been length) was >=
sizeof(buffer), the code logged a truncation warning but then still
memcpy'd that full, untruncated length out of the 4096-byte stack
buffer, reading past its end. retval is now clamped to what vsnprintf
actually wrote before use.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY
This commit is contained in:
Henrik RydgårdandClaude Sonnet 5 committed 2026-08-10 01:00:28 +02:00
1 parent be3b417461
commit 27dcde7419
1 file changed
+4 -1
+4 -1
View File
@@ -103,8 +103,11 @@ void Buffer::Printf(const char *fmt, ...) {
va_start(vl, fmt);
int retval = vsnprintf(buffer, sizeof(buffer), fmt, vl);
if (retval >= (int)sizeof(buffer)) {
// Output was truncated. TODO: Do something.
// Output was truncated. vsnprintf returns the length it would have written,
// but buffer only actually holds sizeof(buffer) - 1 chars (plus the NUL) -
// clamp so we don't copy past what was actually written into it.
ERROR_LOG(Log::IO, "Buffer::Printf truncated output");
retval = (int)sizeof(buffer) - 1;
}
va_end(vl);
if (retval < 0) {