Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #716.
When I use the WebView to load HTML, I've noticed that a vertical scroll bar occasionally appears on the right side, but this behavior isn't consistently reproducible. After a build, unexpected garbage characters always appear at the end of the HTML, which is the cause of the scrollbar. This is obviously a buffer overflow.
The problem is that C++'s
std::string_viewdoes not guarantee that it is'\0'terminated.cppref:
In my use case, the HTML comes from a char array generated by
xxd, which is not'\0'terminated. After it is passed towebui, subsequent calls tostrlenand further string operations lead to a buffer overflow.If strings themselves come from
std::stringorchar const [], they will not be affected by this vulnerability.With the assistance of AI, I successfully wrote a PoC. If the parameters come from user-controlled input, under specific usage scenarios, the resulting buffer overflow can eventually reach the
systemcall, enabling multiple RCE exploits.This PR is a quick mitigation. If we want to preserve the zero-copy advantage of
std::string_view, we may need to modify the C API to accept an additional length parameter.