Commit dc1145e3a3a for php
commit dc1145e3a3a2796d9166678f2909f13c3486768c
Author: Daniel Scherzer <daniel.e.scherzer+phpf@gmail.com>
Date: Mon Sep 28 17:35:45 2026 -0700
ext/iconv: add a hardening assertion that `char_cnt` doesn't underflow (#23873)
diff --git a/ext/iconv/iconv.c b/ext/iconv/iconv.c
index af4717a00a4..dad797ee14b 100644
--- a/ext/iconv/iconv.c
+++ b/ext/iconv/iconv.c
@@ -1102,6 +1102,12 @@ static php_iconv_err_t _php_iconv_mime_encode(smart_str *pretval, const char *fn
const unsigned char *p;
size_t nbytes_required;
+ /* Some agents get confused about what char_cnt is; it will
+ * be at least 4 at this point; if caller messed up and gave
+ * too short of a max_line_len that was already caught above
+ * and handled with PHP_ICONV_ERR_TOO_BIG. */
+ ZEND_ASSERT(char_cnt >= 4);
+
smart_str_appendc(pretval, 'Q');
char_cnt--;
smart_str_appendc(pretval, '?');