mirror of https://github.com/icsharpcode/ILSpy.git
Tree:
bc8b1d1893
christophwille/closedhierarchies
christophwille/membench
compound-assignment-operators
fix/1982-params-attribute-args
fix/2040-invalid-xml-characters
fix/2093-navigateto-reference-assembly
fix/2362-xalz-references
fix/2372-address-taken-by
fix/3282-indexer-optional-arguments
fix/3568-record-member-order
fix/4059-deconstruct-out-slots
fix/lambda-parameter-syntax
fix/scroll-children-on-expand
gh-pages
ldmembertoken
master
natural-type-lambdas-methods
null-coalescing-assignment
release/10.1
release/6.2
release/7.1
release/7.2
release/8.1
substring-optimizations
tests/829-async-method-builder-override
tests/829-collection-expressions
tests/829-compound-assignment-operators
tests/829-coverage-audit
tests/829-expression-tree-named-optional-args
tests/829-expression-variables-in-initializers
tests/829-extended-property-patterns
tests/829-extension-members
tests/829-extension-operators
tests/829-file-local-types
tests/829-improved-definite-assignment
tests/829-improved-overload-candidates
tests/829-inline-arrays
tests/829-interpolated-string-improvements
tests/829-lambda-param-modifiers
tests/829-list-patterns
tests/829-lock-object
tests/829-mixed-deconstruction
tests/829-null-coalescing-assignment
tests/829-null-conditional-assignment
tests/829-object-initializer-indexer
tests/829-overload-resolution-priority
tests/829-params-collections
tests/829-pattern-matching-improvements
tests/829-primary-constructors
tests/829-ref-unsafe-in-iterators-async
tests/829-sealed-record-tostring
tests/829-target-typed-conditional
tests/829-tuple-comparison
win-a11y-textsize
1.0-Beta
1.0-M1
1.0-M2
1.0-M3
1.0.0
2.0.0
2.1
2.2
2.3
2.3.1
3.0-Preview1
3.0-Preview2
3.0.2
v10.0
v10.0-preview1
v10.0-preview2
v10.0-preview3
v10.0.1
v10.1
v10.1.1
v11.0
v11.0-preview1
v11.0-rc
v2.3.2
v2.4
v3.0
v3.0-beta1
v3.0-beta2
v3.0-beta2a
v3.0-beta3
v3.0-beta4
v3.0.1
v3.1-beta1
v3.1-final
v3.1-rc
v3.2-beta
v3.2-rc
v3.2.0
v4.0
v4.0-alpha1
v4.0-beta1
v4.0-beta2
v4.0-beta3
v4.0-rc1
v4.0-rc2
v4.0.1
v5.0
v5.0-preview1
v5.0-preview2
v5.0-preview3
v5.0-preview4
v5.0-rc1
v5.0.1
v5.0.2
v6.0
v6.0-preview1
v6.0-preview2
v6.0-preview3
v6.0-preview4
v6.0-rc1
v6.1
v6.2
v6.2-preview1
v6.2-preview2
v6.2.1
v7.0
v7.0-preview1
v7.0-preview2
v7.0-preview3
v7.0-rc1
v7.0-rc2
v7.1
v7.2
v7.2-preview1
v7.2-preview2
v7.2-preview3
v7.2-preview4
v7.2-rc
v7.2.1
v8.0
v8.0-preview1
v8.0-preview2
v8.0-preview3
v8.0-preview4
v8.0-rc1
v8.1
v8.1.1
v8.2
v9.0
v9.0-preview1
v9.0-preview2
v9.0-preview3
v9.0-rc
v9.1
${ noResults }
1 Commits (bc8b1d1893097e6db5f7ede6c078110ddb8b33cb)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
c685d5305b |
Bound XamarinCompressedFileLoader against crafted XALZ headers
The Xamarin XALZ loader sized its buffer allocations from an attacker-controlled header field and ignored the partial-read length, so merely opening a crafted file (the loader is registered first and runs on any XALZ-magic input) could crash or over-allocate. The declared uncompressed length, a raw header uint cast to int, had no sanity bound: a tiny file claiming ~2 GB forced a giant ArrayPool.Rent (decompression-bomb amplification), and a high-bit value became negative and made Rent throw ArgumentOutOfRangeException. The compressed length was taken as the whole file (header included) and ReadAsync's return value was discarded, leaving stale pooled bytes in the tail fed to the decoder; the output MemoryStream then exposed the entire rented buffer, so PEFile parsed past the real decompressed data into leftover pool contents. Bound the declared length before renting (reject zero, > int.MaxValue, or more than an LZ4 block could expand from this payload at its 255x maximum ratio), read the payload that actually follows the header with ReadExactlyAsync, and slice the output to the length LZ4Codec.Decode reports. Malformed input now fails as a catchable InvalidDataException, consistent with the bundle and .rsrc hardening; well-formed Xamarin modules load exactly as before. Assisted-by: Claude:claude-opus-4-8:Claude Code |
2 months ago |