From f168c10b52325b00da6355989a18a11743b33f89 Mon Sep 17 00:00:00 2001 From: Comtea04 Date: Sun, 27 Sep 2026 15:06:22 +0900 Subject: bytearray: Handle realloc() failure in byte_array_grow() byte_array_grow() assigned the result of realloc() directly to ba->data and increased the capacity even if realloc() failed, so the following memcpy() in byte_array_append() wrote to NULL + len. On failure, free the old buffer and leave the byte array in a failed state (data == NULL), which byte_array_append() already ignores. The callers check for that state: - the writers (bin, xml, json, openstep and the text output formats) return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer - node_to_xml() base64-encodes directly into the grown buffer, so it must bail out there (only guarded by assert() before) - the OpenStep parser returns PLIST_ERR_NO_MEM for instead of silently returning truncated data Co-Authored-By: Claude Opus 5.5 --- src/oplist.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) (limited to 'src/oplist.c') diff --git a/src/oplist.c b/src/oplist.c index 77a99cd..a635302 100644 --- a/src/oplist.c +++ b/src/oplist.c @@ -531,6 +531,13 @@ plist_err_t plist_to_openstep_with_options(plist_t plist, char **openstep, uint3 str_buf_append(outbuf, "\0", 1); + if (!outbuf->data) { + str_buf_free(outbuf); + *openstep = NULL; + *length = 0; + return PLIST_ERR_NO_MEM; + } + *openstep = (char*)outbuf->data; *length = outbuf->len - 1; @@ -780,6 +787,11 @@ static plist_err_t node_from_openstep(parse_ctx ctx, plist_t *plist) } b = (b << 4) + HEX_DIGIT(*ctx->pos); byte_array_append(bytes, &b, 1); + if (!bytes->data) { + PLIST_OSTEP_ERR("Out of memory while parsing data at offset %ld\n", (long int)(ctx->pos - ctx->start)); + ctx->err = PLIST_ERR_NO_MEM; + break; + } ctx->pos++; } if (ctx->err) { -- cgit v1.1-32-gdbae