Skip to content

fix(simd): NEON vfloat4::load(values,n) read past the end of the buffer - #5404

Merged
lgritz merged 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-neon-partial-load
Aug 16, 2026
Merged

fix(simd): NEON vfloat4::load(values,n) read past the end of the buffer#5404
lgritz merged 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-neon-partial-load

Conversation

@lgritz

@lgritz lgritz commented Aug 15, 2026

Copy link
Copy Markdown
Collaborator

The NEON branch loaded all 4 lanes with vld1q_f32 and then zeroed the ones it didn't want, so a partial load of n<4 elements read up to 12 bytes past the caller's buffer. ASan flags it as a heap-buffer-overflow of size 16. The SSE branch gets this right by switching on n before loading.

Within OIIO the over-read has been harmless, because imagebuf.cpp and imagecache.cpp deliberately pad their allocations by OIIO_SIMD_MAX_SIZE_BYTES to permit exactly this. But simd.h is a public header, and a downstream caller has no reason to expect a 4-element load to touch 16 bytes.

Also, n==0 fell through to default: after the load without zeroing anything, returning the over-read garbage instead of zeros.

Assisted-by: Claude Code / claude-opus-5

The NEON branch loaded all 4 lanes with vld1q_f32 and then zeroed the ones
it didn't want, so a partial load of n<4 elements read up to 12 bytes past
the caller's buffer. ASan flags it as a heap-buffer-overflow of size 16.
The SSE branch gets this right by switching on n before loading.

Within OIIO the over-read has been harmless, because imagebuf.cpp and
imagecache.cpp deliberately pad their allocations by OIIO_SIMD_MAX_SIZE_BYTES
to permit exactly this. But simd.h is a public header, and a downstream
caller has no reason to expect a 4-element load to touch 16 bytes.

Also, n==0 fell through to `default:` after the load without zeroing
anything, returning the over-read garbage instead of zeros.

Assisted-by: Claude Code / claude-opus-5

Signed-off-by: Larry Gritz <lg@larrygritz.com>

@jinhgkim jinhgkim left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me

@lgritz
lgritz merged commit 5b6143a into AcademySoftwareFoundation:main Aug 16, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants