pjfanning opened a new pull request, #1347:
URL: https://github.com/apache/poi/pull/1347
`CryptoAPIDecryptor.getSummaryEntries` reads the stream descriptor count as
an unsigned 32-bit field and uses it directly as an array length, with **no
bound at all**:
```java
int encryptedStreamDescriptorCount = Math.toIntExact(leis.readUInt());
StreamDescriptorEntry[] entries = new
StreamDescriptorEntry[encryptedStreamDescriptorCount];
```
A crafted encrypted stream can therefore ask for a billion-element
`StreamDescriptorEntry[]` from a handful of input bytes, before any entry data
is read.
### Approach
Rather than cap the count — any cap would be a guess, and could reject a
valid document — the entries are now collected as they are parsed:
```java
final long encryptedStreamDescriptorCount = leis.readUInt();
List<StreamDescriptorEntry> entries = new ArrayList<>();
for (long i = 0; i < encryptedStreamDescriptorCount; i++) { ... }
```
Memory used is now proportional to the data actually present. A count larger
than the stream can back hits end-of-file — `LittleEndianInputStream.checkEOF`
throws on a short read — which the method's existing `catch` already turns into
`IOException("summary entries can't be read")`. **No limit is imposed on well
formed input**, so a document with an unusually large number of streams still
parses as before.
`entries` was only consumed by an enhanced-for loop, so a `List` drops in
for the array.
### Context
Found while sweeping `Math.toIntExact` call sites after #1345. It was the
only genuinely unbounded allocation the sweep turned up; the separate
`HwmfBitmapDib` cleanup is #1346.
### Tests
`:poi:test --tests 'org.apache.poi.poifs.crypt.*'` passes (23 tests).
Leaving the rest to CI.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]