Skip to content

Increase device_info name buffer to avoid stack corruption on CUDA - #389

Open
phil-opp wants to merge 1 commit into
arrayfire:masterfrom
phil-opp:fix-device-info-buffer-overflow
Open

Increase device_info name buffer to avoid stack corruption on CUDA#389
phil-opp wants to merge 1 commit into
arrayfire:masterfrom
phil-opp:fix-device-info-buffer-overflow

Conversation

@phil-opp

@phil-opp phil-opp commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

The name buffer in device_info matched ArrayFire's documented minimum
size of 64 bytes, but af_device_info takes no length arguments and the
CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations
without stopping at the NUL terminator, so it reads d_name[0..256] and
writes up to d_name[255] on every call, regardless of the actual device
name length. That overflows the 64-byte buffer by ~193 bytes, clobbering
the adjacent buffers, spilled registers, the stack cookie and the return
address.

Enlarge the name buffer to 1024 bytes so the call is safe against every
3.8.x backend, independent of any upstream fix. The other three buffers
are left at their documented sizes; no overflow has been demonstrated
for them, and they are no longer in the blast radius.

Backend-side bug: arrayfire/arrayfire#3712

Fixes #384

Co-Authored-By: Claude Opus 5

The name buffer in device_info matched ArrayFire's documented minimum
size of 64 bytes, but af_device_info takes no length arguments and the
CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations
without stopping at the NUL terminator, so it reads d_name[0..256] and
writes up to d_name[255] on every call, regardless of the actual device
name length. That overflows the 64-byte buffer by ~193 bytes, clobbering
the adjacent buffers, spilled registers, the stack cookie and the return
address.

Enlarge the name buffer to 1024 bytes so the call is safe against every
3.8.x backend, independent of any upstream fix. The other three buffers
are left at their documented sizes; no overflow has been demonstrated
for them, and they are no longer in the blast radius.

Backend-side bug: arrayfire/arrayfire#3712
Fixes arrayfire#384

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] device_info() buffers are 64 bytes; CUDA backend writes 257, corrupting the stack

1 participant