Conversation
Add bounds validation to all glTF accessor data copy functions to prevent out-of-bounds heap reads when processing crafted .glb/.gltf files with malicious byteOffset, byteLength, or byteStride values. The glTF decoder trusted accessor/bufferView fields from the input file without validating them against the actual buffer size. A crafted .glb file could cause memcpy to read past the end of the allocated buffer, leading to heap-buffer-overflow (confirmed via AddressSanitizer). Affected functions: - TinyGltfUtils::CopyDataAsFloatImpl() in tiny_gltf_utils.h - CopyDataAsUint32() in gltf_decoder.cc - CopyDataAs<T>() (both specializations) in gltf_decoder.cc - CopyDataFromBufferView() in gltf_decoder.cc
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
|
@googlebot I fixed this |
|
Thanks for confirming the impact and advocating for the fix to land. Quick clarification on authorship**: I am the author of PR #1165 (handle @Sebasteuo)**. The CLA is now signed, so the maintainers can proceed with review. Happy to coordinate if you have additional test cases or related findings. |
|
Closing this PR as the issue is fixed in merged PR #1214. |
|
@igorvytyaz thanks for looking at this. One technical point before #1214 only patches CopyDataAsFloatImpl() in tiny_gltf_utils.h. This
Those take the same untrusted byteOffset, byteLength and byteStride Happy to rebase this PR down to just those four functions so it One other thing worth noting for the record... this PR was opened on |
Add bounds validation to all glTF accessor data copy functions to prevent out-of-bounds heap reads when processing crafted .glb/.gltf files with malicious byteOffset, byteLength, or byteStride values.
The glTF decoder trusted accessor/bufferView fields from the input file without validating them against the actual buffer size. A crafted .glb file could cause memcpy to read past the end of the allocated buffer, leading to heap-buffer-overflow (confirmed via AddressSanitizer).
Affected functions: