Tuesday, September 29, 2026

CFXMLParser 7-Byte Crasher

Nicolas Seriot:

// "<a>" in UTF-16 LE + a single dangling byte
const UInt8 bytes[] = {'<', 0, 'a', 0, '>', 0, 'X'};

[…]

The whole bug is a confusion between bytes left versus UTF-16 characters left. The result is repeated buffer doubling until allocation fails, and a local process crash if the exception is uncaught.

Comments RSS · Twitter · Mastodon

Leave a Comment