mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
Buffer::Printf: fix OOB stack read on vsnprintf truncation
When vsnprintf's return value (the would-have-been length) was >= sizeof(buffer), the code logged a truncation warning but then still memcpy'd that full, untruncated length out of the 4096-byte stack buffer, reading past its end. retval is now clamped to what vsnprintf actually wrote before use. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY
This commit is contained in:
1 parent
be3b417461
commit
27dcde7419
1 file changed
+4
-1
+4
-1
@@ -103,8 +103,11 @@ void Buffer::Printf(const char *fmt, ...) {
|
||||
va_start(vl, fmt);
|
||||
int retval = vsnprintf(buffer, sizeof(buffer), fmt, vl);
|
||||
if (retval >= (int)sizeof(buffer)) {
|
||||
// Output was truncated. TODO: Do something.
|
||||
// Output was truncated. vsnprintf returns the length it would have written,
|
||||
// but buffer only actually holds sizeof(buffer) - 1 chars (plus the NUL) -
|
||||
// clamp so we don't copy past what was actually written into it.
|
||||
ERROR_LOG(Log::IO, "Buffer::Printf truncated output");
|
||||
retval = (int)sizeof(buffer) - 1;
|
||||
}
|
||||
va_end(vl);
|
||||
if (retval < 0) {
|
||||
|
||||
Reference in new issue
Block a user