Increase device_info name buffer to avoid stack corruption on CUDA - #389
Open
phil-opp wants to merge 1 commit into
Open
Increase device_info name buffer to avoid stack corruption on CUDA#389phil-opp wants to merge 1 commit into
phil-opp wants to merge 1 commit into
Conversation
The name buffer in device_info matched ArrayFire's documented minimum size of 64 bytes, but af_device_info takes no length arguments and the CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations without stopping at the NUL terminator, so it reads d_name[0..256] and writes up to d_name[255] on every call, regardless of the actual device name length. That overflows the 64-byte buffer by ~193 bytes, clobbering the adjacent buffers, spilled registers, the stack cookie and the return address. Enlarge the name buffer to 1024 bytes so the call is safe against every 3.8.x backend, independent of any upstream fix. The other three buffers are left at their documented sizes; no overflow has been demonstrated for them, and they are no longer in the blast radius. Backend-side bug: arrayfire/arrayfire#3712 Fixes arrayfire#384 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The name buffer in device_info matched ArrayFire's documented minimum
size of 64 bytes, but af_device_info takes no length arguments and the
CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations
without stopping at the NUL terminator, so it reads d_name[0..256] and
writes up to d_name[255] on every call, regardless of the actual device
name length. That overflows the 64-byte buffer by ~193 bytes, clobbering
the adjacent buffers, spilled registers, the stack cookie and the return
address.
Enlarge the name buffer to 1024 bytes so the call is safe against every
3.8.x backend, independent of any upstream fix. The other three buffers
are left at their documented sizes; no overflow has been demonstrated
for them, and they are no longer in the blast radius.
Backend-side bug: arrayfire/arrayfire#3712
Fixes #384
Co-Authored-By: Claude Opus 5