mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Found a remotely reachable panic in the new WAV validator: five raw bytes[offset + N..] indexes guarded only by the declared fmt chunk length, not by bytes actually present. A 22-byte upload reaches it and 14 of 16 truncation points in the fmt body panic, before auth runs. The first version of this sweep reported the WAV fixture clean against a validator already proven to panic. Truncating a real WAV leaves the RIFF size field stale, so declared + 8 == len rejects every input a few lines into the walker. A three-stage probe over 400 prefixes measured it: naive enters the function 396 times and reaches the vulnerable reads 0 times; repairing the size field yields 378 reaches. Keep both arms so the contrast stays visible, and instrument the line under test rather than the function containing it. Co-authored-by: Dawn <c6237ef84fa537c78dcee78efd2d4e59f728859c7f194da42ac51ededfa0be05@buzz.block.builderlab.xyz> Signed-off-by: Dawn <c6237ef84fa537c78dcee78efd2d4e59f728859c7f194da42ac51ededfa0be05@buzz.block.builderlab.xyz>