Skip to content

Fix INT64_MIN block_count DoS in C SDK - #4034

Open
kalt2212 wants to merge 1 commit into
apache:mainfrom
kalt2212:fix-int64min-blockcount
Open

kalt2212 wants to merge 1 commit into
apache:mainfrom
kalt2212:fix-int64min-blockcount

Conversation

@kalt2212

@kalt2212 kalt2212 commented Oct 9, 2026

Copy link
Copy Markdown

Summary

Fixes a signed integer overflow / denial of service in the Apache Avro C SDK's array and map value readers.

Details

In read_array_value() and read_map_value() (lang/c/src/value-read.c), a negative block_count from the wire is negated with block_count * -1. When block_count == INT64_MIN, the negation is undefined behavior; in practice the value stays negative (or wraps), and the subsequent while (block_count != 0) loop iterates ~2^63 times, hanging the process on just 11 bytes of input (a trivial remote DoS).

The patch rejects INT64_MIN explicitly with avro_set_error("Invalid array block count") / avro_set_error("Invalid map block count") and returns EINVAL, mirroring how other invalid encodings are handled.

Testing

  • PoC verified before the fix: 11-byte input with block_count = INT64_MIN hangs the process; after the fix it returns EINVAL immediately.
  • Existing C SDK test suite passes.

AI tool use disclosure: AI was used in part for code audit and patch drafting.

@github-actions github-actions Bot added the C label Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant