From ca2ba4874904a36409fd5784f6362682936fd439 Mon Sep 17 00:00:00 2001 From: Philipp Oppermann Date: Mon, 3 Aug 2026 14:22:39 +0000 Subject: [PATCH] Increase device_info name buffer to avoid stack corruption on CUDA The name buffer in device_info matched ArrayFire's documented minimum size of 64 bytes, but af_device_info takes no length arguments and the CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations without stopping at the NUL terminator, so it reads d_name[0..256] and writes up to d_name[255] on every call, regardless of the actual device name length. That overflows the 64-byte buffer by ~193 bytes, clobbering the adjacent buffers, spilled registers, the stack cookie and the return address. Enlarge the name buffer to 1024 bytes so the call is safe against every 3.8.x backend, independent of any upstream fix. The other three buffers are left at their documented sizes; no overflow has been demonstrated for them, and they are no longer in the blast radius. Backend-side bug: https://github.com/arrayfire/arrayfire/issues/3712 Fixes #384 Co-Authored-By: Claude Opus 5 (1M context) --- src/core/device.rs | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/src/core/device.rs b/src/core/device.rs index 6f2f80d5..95845198 100644 --- a/src/core/device.rs +++ b/src/core/device.rs @@ -107,7 +107,14 @@ pub fn info_string(verbose: bool) -> String { /// # Return Values /// A tuple of `String` indicating the name, platform, toolkit and compute. pub fn device_info() -> (String, String, String, String) { - let mut name: [c_char; 64] = [0; 64]; + // The documented minimum size for the name buffer is 64 bytes, but + // `af_device_info` takes no length arguments and the CUDA backend writes up + // to 257 bytes into it, corrupting the caller's stack on every call. + // libarrayfire is linked dynamically and this crate never checks its + // version, so an upstream fix is not on its own a reason to shrink this + // back: the library resolved at runtime may still be an affected build. + // See https://github.com/arrayfire/arrayfire/issues/3712 + let mut name: [c_char; 1024] = [0; 1024]; let mut platform: [c_char; 10] = [0; 10]; let mut toolkit: [c_char; 64] = [0; 64]; let mut compute: [c_char; 10] = [0; 10];