Investigate clientChannels[] out of bounds read/crash
I maintainer di solito rispondono entro 3 giorni
@ann0see ci sta già lavorando.
Dal 27/8/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Describe the bug
INVALID_INDEX might not be checked everywhere correctly. AI found out that there could be an out of bounds read possiblity in client.cpp if calling SetRemoteChanGain:
To Reproduce
Not tested. Would probably need some server side trigger with invalid Channel ID.
Probably worth checking on the protocol level for invalid IDs.
Ox Alpha (GLM 5.3-Flash) suggested:
Guard the call site (minimal change):
if ( iChanID != INVALID_INDEX && bMuteMeInPersonalMix ) { ... }
and/or reject invalid IDs in EvaluateClientIDMes; optionally add a defensive Q_ASSERT/range check in SetRemoteChanGain/SetRemoteChanPan mirroring OnControllerInFaderLevel (client.cpp:956). Related latent gap: OnControllerInPanValue (client.cpp:965-975) lacks the bounds check its fader sibling has.
Expected behavior
No crash
AI analysis
src/protocol.cpp:1046-1063(EvaluateClientIDMes) — validates only body size (1 byte); the ID value itself (0–255) is passed through unchecked.src/client.cpp:1010-1036(CClient::OnClientIDReceived):
int iChanID = FindClientChannel ( iServerChanID, true ); // should always return channel 0
...
if ( bMuteMeInPersonalMix )
{
SetRemoteChanGain ( iChanID, 0, false ); // iChanID can be INVALID_INDEX (-1)
}
src/client.cpp:1833-1885(FindClientChannel) returnsINVALID_INDEX(-1) wheniServerChannelID < 0 || >= MAX_NUM_CHANNELSor when all 150 client channel slots are occupied.src/client.cpp:506-539(SetRemoteChanGain):&clientChannels[iId]with no bounds check →- timer inactive: OOB write at
client.cpp:535(clientChan->oldGain = clientChan->newGain = fGain;) plus OOB read ofiServerChannelIDfed toChannel.SetRemoteChanGain()(that callee is range-checked,channel.cpp:302); - timer active: OOB write at
client.cpp:522, andminGainOrPanId = -1causesOnTimerRemoteChanGainOrPan(client.cpp:546-548) to iterate from index −1 afterwards.
- timer inactive: OOB write at
clientChannelsis a fixedCClientChannel[150]member array (src/client.h:392).
Contrast with the correct pattern used 700 lines earlier: OnMuteStateHasChangedReceived checks if ( iChanID != INVALID_INDEX ) (client.cpp:340-346).
- Lingua principale
- C
- Stelle
- 1.1k
- Fork
- 248
- Merge medio
- 2g 22h
- PR unite (30g)
- 6
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di jamulussoftware/jamulus
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
jamulussoftware/jamulus#3953 · 2 commenti ·
I maintainer di solito rispondono entro 3 giorni
-
AI bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
jamulussoftware/jamulus#3901 · 4 commenti · 1 reazione ·
I maintainer di solito rispondono entro 3 giorni
-
AI
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
jamulussoftware/jamulus#3846 ·
I maintainer di solito rispondono entro 3 giorni
-
Qt6 moving towards cmakeApertafeature request
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
jamulussoftware/jamulus#3964 · 3 commenti ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
jamulussoftware/jamulus#3961 ·
I maintainer di solito rispondono entro 3 giorni
Tutte le issue di jamulussoftware/jamulus
Issue simili
-
feature request
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
BasedHardware/omi#20271 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
ImageMagick/ImageMagick#8994 ·
I maintainer di solito rispondono entro 1 giorno
-
area/ysql kind/bug priority/medium
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
yugabyte/yugabyte-db#34552 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
flux-framework/flux-coral2#509 ·