0xiviel/poc-avro-cython-overflow
PoC: fastavro Cython read_long() Integer Overflow Summary The fastavro Cython extension's read_long() function uses a 64-bit unsigned integer (ulong64) for the varint accumulator. When a crafted varint has more than 9 continuation bytes (shift >= 70 bits), the shift operation causes undefined behavior in C, producing completely wrong decoded values. Confirmed on fastavro 1.12.1 — Cython and Python produce different results for the same input. Root… See the full description on the dataset page: https://huggingface.co/datasets/0xiviel/poc-avro-cython-overflow.
Conversations for this repository live on Hugging Face.
CoolFace shows imported repositories read-only. Posting into someone else’s repository from here would need an authorised integration and the account holder’s consent, so the link goes to the source instead.
Open discussions on Hugging Face