Generated code can read and write out of bounds in safe code
Critical severity
GitHub Reviewed
Published
Jun 16, 2022
to the GitHub Advisory Database
•
Updated Jan 8, 2023
Description
Published to the GitHub Advisory Database
Jun 16, 2022
Reviewed
Jun 16, 2022
Last updated
Jan 8, 2023
Code generated by flatbuffers' compiler is
unsafe
but not marked as such.See google/flatbuffers#6627 for details.
All users that use generated code by
flatbuffers
compiler are recommended to:follow
,push
, or any method that uses them(e.g.
self_follow
).intended to be used.
References