Skip to content

mesh: validate num_faces against buffer capacity in Edgebreaker (fixes #1169) - #1242

Open
jdymitarai wants to merge 1 commit into
google:mainfrom
jdymitarai:fix-edgebreaker-uncontrolled-alloc-1169
Open

jdymitarai wants to merge 1 commit into
google:mainfrom
jdymitarai:fix-edgebreaker-uncontrolled-alloc-1169

Conversation

@jdymitarai

Copy link
Copy Markdown

Root Cause

In MeshEdgebreakerDecoderImpl::DecodeConnectivity() (src/draco/compression/mesh/mesh_edgebreaker_decoder_impl.cc), num_faces is decoded from untrusted input buffer and validated only against std::numeric_limits<CornerIndex::ValueType>::max() / 3. However, the decoder never validates that num_faces can realistically fit within the remaining buffer size. When a crafted input supplies a large num_faces (such as 0x33333333 in the 61-byte PoC of #1169), subsequent allocations in processed_corner_ids_.reserve(num_faces) and corner_table_->Reset(num_faces, ...) attempt multi-gigabyte memory allocations, triggering uncontrolled memory allocation (CWE-789) and DoS crashes.

Fix

Similar to the bounds checks in MeshSequentialDecoder::DecodeConnectivity() and AttributesDecoder::DecodeAttributesDecoderData(), validate num_faces against the remaining buffer capacity before performing memory allocations or graph connectivity setup. If num_faces > 0 and the remaining buffer size is non-positive or insufficient to hold the minimum bits required for that many faces, reject decoding by returning false.

Verification

Added a regression test MeshEdgebreakerEncodingTest.RejectMalformedOversizedFaces in src/draco/compression/mesh/mesh_edgebreaker_encoding_test.cc using the 61-byte Base64 PoC from issue #1169. Verified that the malformed input is safely rejected with an error status without triggering excessive memory allocation or crashes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant