The GitHub Actions job "Java CI with Ant" on poi.git/hemf-bounds-check-before-narrowing has succeeded. Run started by GitHub user pjfanning (triggered by pjfanning).
Head commit for run: 98c2625e06e99dd58b7962dc23b6cbbe2c4c40b0 / PJ Fanning <[email protected]> Bounds check untrusted 32-bit counts before narrowing them to int Several parsers read an unsigned 32-bit count or size field, narrow it with Math.toIntExact, and only then range check it. For a field above Integer.MAX_VALUE the narrowing throws ArithmeticException first, so the check that follows never runs and the caller sees an unrelated exception instead of the RecordFormatException the guards are written to produce. Keep these values as longs until after the check. The IOUtils/ArrayUtil checkers already take a long and already reject both negative and over-Integer.MAX_VALUE lengths with a descriptive message. Sites changed: * HemfDraw.EmfPolyBezier / EmfPolygon - the spec says extra points MUST be ignored and the code caps the count at 16K, but the narrowing ran first, so an oversized count was rejected instead of clamped. * HemfDraw.EmfPolyDraw - narrowing pre-empted HemfPicture.safelyAllocateCheck. * HemfComment.EmfCommentDataBeginGroup / EmfCommentDataWMF - narrowing pre-empted IOUtils.safelyAllocate. * hpsf Section.readDictionary - the oversize test sits outside the try/catch that records a corrupted dictionary, so the narrowing threw ArithmeticException out of the Section constructor rather than taking the corrupted-dictionary path. Reported for the EMF records by a security researcher. The EMF paths are not themselves an availability problem: HemfRecordIterator already wraps any RuntimeException into RecordFormatException, and the allocation guards themselves were added in #1104, #1107 and #1114. This corrects the ordering so the guards report what they were meant to report. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> Report URL: https://github.com/apache/poi/actions/runs/35726034111 With regards, GitHub Actions via GitBox --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
