pjfanning opened a new pull request, #1346: URL: https://github.com/apache/poi/pull/1346
Follow-up to #1345. That PR fixed the sites the security report named; this one is the result of sweeping **every** `Math.toIntExact` in the main sources whose result feeds an array allocation or an `IOUtils`/`ArrayUtil` call (15 sites), and checking each by hand. Two needed a change. ### `CryptoAPIDecryptor.getSummaryEntries` The stream descriptor count is an unsigned 32-bit field used directly as an array length, with **no bound at all**: ```java int encryptedStreamDescriptorCount = Math.toIntExact(leis.readUInt()); StreamDescriptorEntry[] entries = new StreamDescriptorEntry[encryptedStreamDescriptorCount]; ``` A crafted encrypted stream could ask for a billion-element `StreamDescriptorEntry[]` from a handful of input bytes. Now routed through `ArrayUtil.safelyAllocateCheck` with a configurable limit, following the `SharedValueManager.setMaxNumberOfFormulaRecordAggregates` idiom. This is the only genuinely unbounded allocation the sweep turned up — unlike the EMF records in the original report, which were already guarded. ### `HwmfBitmapDib.getBMPData` The size is derived from `headerImageSize`, an unsigned 32-bit DIB header field. Narrowing first meant an over-large value threw `ArithmeticException` instead of the `RecordFormatException` that `IOUtils.safelyAllocate` reports. Kept as a `long` until after the allocation bounds it. ### Checked and left alone Already guarded before the narrowing, so `toIntExact` cannot throw: | Site | Existing guard | |---|---| | `ZipArchiveFakeEntry` | `entrySize >= Integer.MAX_VALUE` | | `hpsf` `Array.ArrayHeader.read` | dimension count constrained to 1..31 | | `hpsf` `Array.read` | scalar count `> Integer.MAX_VALUE` | | `hpbf` `QuillContents` | offset and length both validated | | `HwmfPicture`, `HwmfBitmapDib.init` | `recordSize` is already an `int` | | `HemfHeader`, `HemfText` | values already clamped to `int` range | ### Tests No new tests here — `:poi:test --tests 'org.apache.poi.poifs.crypt.*'` and `:poi-scratchpad:test --tests 'org.apache.poi.hwmf.*'` pass (48 tests). Leaving the rest to CI. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
