dxbjavid opened a new pull request, #3597:
URL: https://github.com/apache/thrift/pull/3597

   readHeaderFormat checks the declared header size against the whole frame 
size, but the parse pointer has already moved past the 10-byte common header 
before that check, so a header size landing in the last 10 bytes of the frame 
leaves the header boundary pointing up to 10 bytes beyond the receive buffer. 
The varint and string readers only stop at that boundary, so a malformed 
THeader frame makes them read past the end of the buffer. Comparing the header 
section against the remaining sz - 10 bytes keeps the boundary inside the 
allocation, and the added test drives the read path with such a frame.
   
   - [ ] Did you create an [Apache 
Jira](https://issues.apache.org/jira/projects/THRIFT/issues/) ticket?  
([Request account here](https://selfserve.apache.org/jira-account.html), not 
required for trivial changes)
   - [ ] If a ticket exists: Does your pull request title follow the pattern 
"THRIFT-NNNN: describe my issue"?
   - [x] Did you squash your changes to a single commit?  (not required, but 
preferred)
   - [x] Did you do your best to avoid breaking changes?  If one was needed, 
did you label the Jira ticket with "Breaking-Change"?
   - [ ] If your change does not involve any code, include `[skip ci]` anywhere 
in the commit message to free up build resources.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to