From 27dcde7419e9fd36ad9d77fbb7081631ab2b9c1d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Henrik=20Rydg=C3=A5rd?= Date: Sun, 9 Aug 2026 15:41:29 +0200 Subject: [PATCH] Buffer::Printf: fix OOB stack read on vsnprintf truncation When vsnprintf's return value (the would-have-been length) was >= sizeof(buffer), the code logged a truncation warning but then still memcpy'd that full, untruncated length out of the 4096-byte stack buffer, reading past its end. retval is now clamped to what vsnprintf actually wrote before use. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY --- Common/Buffer.cpp | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/Common/Buffer.cpp b/Common/Buffer.cpp index a6cd052729..a7e02df8b0 100644 --- a/Common/Buffer.cpp +++ b/Common/Buffer.cpp @@ -103,8 +103,11 @@ void Buffer::Printf(const char *fmt, ...) { va_start(vl, fmt); int retval = vsnprintf(buffer, sizeof(buffer), fmt, vl); if (retval >= (int)sizeof(buffer)) { - // Output was truncated. TODO: Do something. + // Output was truncated. vsnprintf returns the length it would have written, + // but buffer only actually holds sizeof(buffer) - 1 chars (plus the NUL) - + // clamp so we don't copy past what was actually written into it. ERROR_LOG(Log::IO, "Buffer::Printf truncated output"); + retval = (int)sizeof(buffer) - 1; } va_end(vl); if (retval < 0) {