windows: avoid uint16 overflow in NewNTUnicodeString

Fixes CVE-2026-39824
Fixes #78916

Change-Id: I344518a17d59fd81c4bb39da0b3e13be6a6a6964
Reviewed-on: https://go-review.googlesource.com/c/sys/+/770080
Reviewed-by: Neal Patel <nealpatel@google.com>
Reviewed-by: Quim Muntal <quimmuntal@gmail.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Damien Neil <dneil@google.com>
This commit is contained in:
Damien Neil
2026-04-23 08:37:02 -07:00
committed by Gopher Robot
parent 94ad893e1e
commit fb1facd76f
2 changed files with 34 additions and 14 deletions
+28 -11
View File
@@ -10,6 +10,7 @@ import (
"debug/pe"
"errors"
"fmt"
"math"
"os"
"os/exec"
"path/filepath"
@@ -1475,21 +1476,37 @@ func TestToUnicodeEx(t *testing.T) {
}
func TestRoundtripNTUnicodeString(t *testing.T) {
for _, s := range []string{
"",
"hello",
"Ƀ",
strings.Repeat("*", 32000), // NTUnicodeString works up to 2^16 byte lengths == 32768 uint16s.
// TODO: various encoding errors?
} {
ntus, err := windows.NewNTUnicodeString(s)
// NTUnicodeString maximum string length must fit in a uint16, less for terminal NUL.
maxString := strings.Repeat("*", (math.MaxUint16/2)-1)
for _, test := range []struct {
s string
wantErr bool
}{{
s: "",
}, {
s: "hello",
}, {
s: "Ƀ",
}, {
s: maxString,
}, {
s: maxString + "*",
wantErr: true,
}, {
s: "a\x00a",
wantErr: true,
}} {
ntus, err := windows.NewNTUnicodeString(test.s)
if (err != nil) != test.wantErr {
t.Errorf("NewNTUnicodeString(%q): %v, wantErr:%v", test.s, err, test.wantErr)
continue
}
if err != nil {
t.Errorf("encoding %q failed: %v", s, err)
continue
}
s2 := ntus.String()
if s != s2 {
t.Errorf("round trip of %q = %q, wanted original", s, s2)
if test.s != s2 {
t.Errorf("round trip of %q = %q, wanted original", test.s, s2)
}
}
}