Skip to content

Fix heap buffer overflow write in loadIndex when max_elements < cur_element_count - #684

Closed
thlurte wants to merge 1 commit into
nmslib:masterfrom
thlurte:fix-loadindex-heap-overflow-673
Closed

thlurte wants to merge 1 commit into
nmslib:masterfrom
thlurte:fix-loadindex-heap-overflow-673

Conversation

@thlurte

@thlurte thlurte commented Sep 22, 2026 •

Copy link
Copy Markdown

Closed.

When loading an index file with a corrupted or crafted header where
max_elements_ < cur_element_count, loadIndex allocates data_level0_memory_
for max_elements_ but reads cur_element_count * size_data_per_element_ bytes,
triggering a heap buffer overflow write.

Validate max_elements_ >= cur_element_count immediately after reading the
header, returning Status("Index seems to be corrupted or unsupported").
Also add test coverage verifying corrupted index headers are rejected safely.

Fixes nmslib#673

Signed-off-by: Ahmed <thlurte@gmail.com>
@thlurte

thlurte commented Sep 22, 2026

Copy link
Copy Markdown
Author

Closed as this was already ported and committed in 730f042 via PR #677.

@thlurte thlurte closed this Sep 22, 2026
@thlurte
thlurte deleted the fix-loadindex-heap-overflow-673 branch September 22, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant