Clamp aligned_offset in MemorySnapshotSanitized MemorySanitizer::Sanitize() computes the number of leading unaligned bytes from the snapshot's base address and uses it as the length of a memcpy into the data buffer and as the subtrahend for the word count. When the snapshot is shorter than the alignment offset (an unaligned base address with a sub-word region), the leading memcpy writes past the end of the buffer and the word count underflows. Clamp the offset to the buffer size so that short unaligned regions are defaced in place. Add MemorySnapshotSanitized.ShortUnalignedRegion64/32 unit tests covering every (offset, size) pair below the pointer width. Bug: 500097298 Change-Id: Ib58b96250631f760329f16d30a0e7b8b062394f2 Reviewed-on: https://chromium-review.googlesource.com/c/crashpad/crashpad/+/8138617 Reviewed-by: Mark Mentovai <mark@chromium.org> Commit-Queue: Joshua Peraza <jperaza@chromium.org>
Crashpad is a crash-reporting system.
Crashpad’s source code is hosted in a Git repository at https://chromium.googlesource.com/crashpad/crashpad.