Commit 8906dc25186 for php
commit 8906dc25186b0e3675ae0e2b57366b0cc7196cbc
Author: Daniel Scherzer <daniel.e.scherzer+phpf@gmail.com>
Date: Mon Sep 28 16:56:03 2026 -0700
ext/mbstring: assert that `mb_wchar_to_uuencode()` pointer write is in bounds (#23955)
Add a hardening assertion that when `mb_wchar_to_uuencode()` needs to update
the length of the previous line, the location being written to is still part of
the same overall output string (i.e. at or after the start of the buffer's
`str`'s value pointer, and before the end of the char array).
diff --git a/ext/mbstring/libmbfl/filters/mbfilter_uuencode.c b/ext/mbstring/libmbfl/filters/mbfilter_uuencode.c
index 600d019b9d4..896b9527971 100644
--- a/ext/mbstring/libmbfl/filters/mbfilter_uuencode.c
+++ b/ext/mbstring/libmbfl/filters/mbfilter_uuencode.c
@@ -287,6 +287,9 @@ static void mb_wchar_to_uuencode(uint32_t *in, size_t len, mb_convert_buf *buf,
if (n_cached_bits) {
len_byte -= (n_cached_bits == 2) ? 1 : 2;
}
+ /* The byte we are writing to must be part of the same buffer */
+ ZEND_ASSERT(len_byte >= (unsigned char *)ZSTR_VAL(buf->str));
+ ZEND_ASSERT(len_byte < limit);
*len_byte = MIN(bytes_encoded + len + (n_cached_bits ? (n_cached_bits == 2 ? 1 : 2) : 0), 45) + 32;
if (n_cached_bits) {