mirror of
https://github.com/nlohmann/json.git
synced 2026-10-02 04:30:29 +00:00
Throw std::length_error for operator[](SIZE_MAX) instead of corrupting the array (#5687)
For idx == SIZE_MAX, the non-const array operator[] computed the new size as idx + 1, which wraps to 0. resize(0) then emptied the array, and the subsequent operator[](idx) on the now-empty vector wrote one element before its buffer. Every other too-large index (e.g. SIZE_MAX - 1) already went through resize(), which throws std::length_error and leaves the array unchanged; SIZE_MAX was the one value for which the overflow bypassed that safety net. Add a guard that throws std::length_error before computing idx + 1 when idx is the largest representable size_type value, so the array is left unchanged, matching the exception vector::resize() already throws for smaller (but still too large) indices. Fixes #5647. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
@@ -36,7 +36,9 @@
|
||||
#include <iosfwd> // istream, ostream
|
||||
#endif // JSON_NO_IO
|
||||
#include <iterator> // make_move_iterator, random_access_iterator_tag
|
||||
#include <limits> // numeric_limits
|
||||
#include <memory> // unique_ptr
|
||||
#include <stdexcept> // length_error
|
||||
#include <string> // string, stoi, to_string
|
||||
#include <utility> // declval, forward, move, pair, swap
|
||||
#include <vector> // vector
|
||||
@@ -2826,6 +2828,13 @@ class basic_json // NOLINT(cppcoreguidelines-special-member-functions,hicpp-spec
|
||||
// fill up the array with null values if given idx is outside the range
|
||||
if (idx >= m_data.m_value.array->size())
|
||||
{
|
||||
// idx + 1 would overflow size_type and wrap to 0, which would empty
|
||||
// the array instead of growing it; reject such an idx the same way
|
||||
// resize() rejects other indices that are too large to represent
|
||||
if (JSON_HEDLEY_UNLIKELY(idx == (std::numeric_limits<size_type>::max)()))
|
||||
{
|
||||
JSON_THROW(std::length_error(detail::concat("array index ", std::to_string(idx), " exceeds size_type")));
|
||||
}
|
||||
#if JSON_DIAGNOSTICS
|
||||
// remember array size & capacity before resizing
|
||||
const auto old_size = m_data.m_value.array->size();
|
||||
|
||||
Reference in New Issue
Block a user