Skip to content

Non-blocking Smile parser should validate raw binary length and not pre-allocate full buffer [CVE-2026-104895] #825

Description

@pjfanning

When the non-blocking Smile parser (NonBlockingByteArrayParser) encounters a raw binary value (0xFD), it allocates a byte[] of the declared length as soon as the length prefix is decoded, before any of the content has arrived. The blocking SmileParser behaves differently: for lengths above LONGEST_NON_CHUNKED_BINARY (250,000) it accumulates content as it is read (_finishBinaryRawLong(), added for #260).

In addition, the async length decoding does not validate the decoded 5-byte VInt the way SmileParser._readUnsignedVInt() does, so a malformed length can come out negative and lead to a NegativeArraySizeException rather than a StreamReadException.

Suggest aligning the non-blocking parser with the blocking one:

  • report a StreamReadException for an invalid (negative) raw binary length
  • for long raw binary values, accumulate content incrementally instead of allocating the full declared length up front

Affects 2.x and 3.x.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

CVEIssues with allocated or published CVEs (security vuln reports)smile

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions