Commit ca2ba48
Increase device_info name buffer to avoid stack corruption on CUDA
The name buffer in device_info matched ArrayFire's documented minimum
size of 64 bytes, but af_device_info takes no length arguments and the
CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations
without stopping at the NUL terminator, so it reads d_name[0..256] and
writes up to d_name[255] on every call, regardless of the actual device
name length. That overflows the 64-byte buffer by ~193 bytes, clobbering
the adjacent buffers, spilled registers, the stack cookie and the return
address.
Enlarge the name buffer to 1024 bytes so the call is safe against every
3.8.x backend, independent of any upstream fix. The other three buffers
are left at their documented sizes; no overflow has been demonstrated
for them, and they are no longer in the blast radius.
Backend-side bug: arrayfire/arrayfire#3712
Fixes #384
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent bd3be3e commit ca2ba48
1 file changed
Lines changed: 8 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
107 | 107 | | |
108 | 108 | | |
109 | 109 | | |
110 | | - | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
111 | 118 | | |
112 | 119 | | |
113 | 120 | | |
| |||
0 commit comments