On Sat, 4 Jul 2026 04:49:54 GMT, David CARLIER <[email protected]> wrote:

> Found while auditing the JVMTI local-variable accessors.
> 
> `VM_BaseGetOrSetLocal` bounds-checks the requested slot before touching the 
> frame's `StackValueCollection`. For a `long`/`double` the value spans two 
> slots, so the check adds an `extra_slot` of 1: `_index + extra_slot >= 
> method->max_locals()`. When an agent passes `slot == INT_MAX`, `_index + 
> extra_slot` signed-overflows to `INT_MIN`, which is below `max_locals()`, so 
> the guard is bypassed and we go on to index `locals->at(INT_MAX)` — out of 
> bounds. That is an assertion failure in fastdebug and a SIGSEGV or silent 
> corruption in product.
> 
> Doing the arithmetic on the other side (`_index >= method->max_locals() - 
> extra_slot`) avoids the overflow. The same check appears in both 
> `check_slot_type_lvt` and `check_slot_type_no_lvt`, so both are fixed.
> 
> Additional testing:
>  - [x] Linux x86_64 server fastdebug, `serviceability/jvmti/GetLocalVariable`
>  - [ ] Regular testing pipelines
> 
> ---------
> - [x] I confirm that I make this contribution in accordance with the [OpenJDK 
> Interim AI Policy](https://openjdk.org/legal/ai).

This pull request has now been integrated.

Changeset: 6987a359
Author:    David CARLIER <[email protected]>
Committer: Serguei Spitsyn <[email protected]>
URL:       
https://git.openjdk.org/jdk/commit/6987a3593fc7581f04992b034d3dbb0469d09f1f
Stats:     192 lines in 3 files changed: 190 ins; 0 del; 2 mod

8387718: JVMTI GetLocal/SetLocal: slot bounds check overflows for long/double 
slots

Reviewed-by: dholmes, sspitsyn

-------------

PR: https://git.openjdk.org/jdk/pull/31772

Reply via email to