Fix Flawfinder: format the BSON element type without snprintf

Moving the report of an unsupported BSON element type into
skip_unsupported_bson_element() moved its snprintf() call, which
Flawfinder then reported as a new CWE-134 finding. The two hexadecimal
digits are now computed directly; the message is unchanged.

Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This commit is contained in:
Niels Lohmann
2026-09-28 20:36:28 +02:00
parent de8529f99b
commit d1d84ed9af
2 changed files with 14 additions and 6 deletions
+7 -3
View File
@@ -13795,9 +13795,13 @@ class binary_reader
*/
bool skip_unsupported_bson_element(const char_int_type element_type, const std::size_t element_type_parse_position)
{
std::array<char, 3> cr{{}};
static_cast<void>((std::snprintf)(cr.data(), cr.size(), "%.2hhX", static_cast<unsigned char>(element_type))); // NOLINT(cppcoreguidelines-pro-type-vararg,hicpp-vararg)
const std::string cr_str{cr.data()};
// the type as two uppercase hexadecimal digits, without a format string
const auto type_byte = static_cast<unsigned int>(static_cast<unsigned char>(element_type));
const auto hex_digit = [](const unsigned int digit)
{
return static_cast<char>(digit < 10 ? '0' + digit : 'A' + (digit - 10));
};
const std::string cr_str{hex_digit(type_byte >> 4u), hex_digit(type_byte & 0x0Fu)};
const auto error = parse_error::create(114, element_type_parse_position, concat("Unsupported BSON record type 0x", cr_str), nullptr);
// the number of bytes to skip, -1 if the value is read differently, or