Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-6856

potential out of bounds read in prefetchRecordPages()

    • Type: Icon: Bug Bug
    • Resolution: Done
    • Priority: Icon: Major - P3 Major - P3
    • 2.2.1, 2.3.0
    • Affects Version/s: None
    • Component/s: Storage
    • None
    • ALL

      It looks like prefetchRecordPages() can read one byte past the end of a matching document:

                          // hit the last page, in case we missed it above
                          _dummy_char += *(result.objdata() + result.objsize());
      

      I think one byte past the end of a document might not be in mapped memory, since I don't think the file, extent, or record structures have footers.

            Assignee:
            milkie@mongodb.com Eric Milkie
            Reporter:
            aaron Aaron Staple
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: