thrift icon indicating copy to clipboard operation
thrift copied to clipboard

Unsafe i32 to usize conversion from network data

Open sumanthakur1976 opened this issue 2 years ago • 0 comments

This patch fixes the problem with uncheckd data conversion read from the network. Currently, code reads data from the network, converts it to i32, and then blindly converts it to usize (so -1 gets converted to -1_usize and causes panic in debug build and huge memory use in release build). This could easily become a security vulnerability.

The fix replaces all as usize casts to try_into style casts.

  • [ ] Did you create an Apache Jira ticket? (Request account here, not required for trivial changes)
  • [ ] If a ticket exists: Does your pull request title follow the pattern "THRIFT-NNNN: describe my issue"?
  • [ ] Did you squash your changes to a single commit? (not required, but preferred)
  • [ ] Did you do your best to avoid breaking changes? If one was needed, did you label the Jira ticket with "Breaking-Change"?
  • [ ] If your change does not involve any code, include [skip ci] anywhere in the commit message to free up build resources.

sumanthakur1976 avatar Apr 17 '23 08:04 sumanthakur1976