ubeddulla opened a new pull request, #3392:
URL: https://github.com/apache/brpc/pull/3392

   MemcacheResponse::PopStore derives value_size by subtracting the reply's 
extras_length and key_length from total_body_length, but unlike its siblings 
PopGet, PopCounter and PopVersion it never checks whether value_size went 
negative before handing it to cutn(&_err, value_size). A server (or 
man-in-the-middle) that returns a STORE/DELETE/FLUSH error reply whose extras 
plus key exceed the body drives value_size below zero, so the huge size_t 
drains the rest of the pipelined buffer into the error string and desyncs the 
following replies on the connection. Add the same value_size < 0 guard the 
sibling parsers already carry.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to