pjfanning opened a new pull request, #1346:
URL: https://github.com/apache/poi/pull/1346

   Follow-up to #1345. That PR fixed the sites the security report named; this 
one is the result of sweeping **every** `Math.toIntExact` in the main sources 
whose result feeds an array allocation or an `IOUtils`/`ArrayUtil` call (15 
sites), and checking each by hand.
   
   Two needed a change.
   
   ### `CryptoAPIDecryptor.getSummaryEntries`
   
   The stream descriptor count is an unsigned 32-bit field used directly as an 
array length, with **no bound at all**:
   
   ```java
   int encryptedStreamDescriptorCount = Math.toIntExact(leis.readUInt());
   StreamDescriptorEntry[] entries = new 
StreamDescriptorEntry[encryptedStreamDescriptorCount];
   ```
   
   A crafted encrypted stream could ask for a billion-element 
`StreamDescriptorEntry[]` from a handful of input bytes. Now routed through 
`ArrayUtil.safelyAllocateCheck` with a configurable limit, following the 
`SharedValueManager.setMaxNumberOfFormulaRecordAggregates` idiom.
   
   This is the only genuinely unbounded allocation the sweep turned up — unlike 
the EMF records in the original report, which were already guarded.
   
   ### `HwmfBitmapDib.getBMPData`
   
   The size is derived from `headerImageSize`, an unsigned 32-bit DIB header 
field. Narrowing first meant an over-large value threw `ArithmeticException` 
instead of the `RecordFormatException` that `IOUtils.safelyAllocate` reports. 
Kept as a `long` until after the allocation bounds it.
   
   ### Checked and left alone
   
   Already guarded before the narrowing, so `toIntExact` cannot throw:
   
   | Site | Existing guard |
   |---|---|
   | `ZipArchiveFakeEntry` | `entrySize >= Integer.MAX_VALUE` |
   | `hpsf` `Array.ArrayHeader.read` | dimension count constrained to 1..31 |
   | `hpsf` `Array.read` | scalar count `> Integer.MAX_VALUE` |
   | `hpbf` `QuillContents` | offset and length both validated |
   | `HwmfPicture`, `HwmfBitmapDib.init` | `recordSize` is already an `int` |
   | `HemfHeader`, `HemfText` | values already clamped to `int` range |
   
   ### Tests
   
   No new tests here — `:poi:test --tests 'org.apache.poi.poifs.crypt.*'` and 
`:poi-scratchpad:test --tests 'org.apache.poi.hwmf.*'` pass (48 tests). Leaving 
the rest to CI.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to