aboutsummaryrefslogtreecommitdiff
path: root/test/functional/legacy/normal_spec.lua
diff options
context:
space:
mode:
authorGregory Anders <8965202+gpanders@users.noreply.github.com>2024-08-19 06:43:06 -0500
committerGitHub <noreply@github.com>2024-08-19 06:43:06 -0500
commit6d997f8068a89703823f1572c56a6331c9e024aa (patch)
tree30cef4140fa7b3017d7a754b508eb159335382d0 /test/functional/legacy/normal_spec.lua
parent33464189bc02b2555e26dc4e9f7b3fbbcdd02490 (diff)
downloadrneovim-6d997f8068a89703823f1572c56a6331c9e024aa.tar.gz
rneovim-6d997f8068a89703823f1572c56a6331c9e024aa.tar.bz2
rneovim-6d997f8068a89703823f1572c56a6331c9e024aa.zip
fix(terminal): handle C0 characters in OSC terminator (#30090)
When a C0 character is present in an OSC terminator (i.e. after the ESC but before a \ (0x5c) or printable character), vterm executes the control character and resets the current string fragment. If the C0 character is the final byte in the sequence, the string fragment has a zero length. However, because the VT parser is still in the "escape" state, vterm attempts to subtract 1 from the string length (to account for the escape character). When the string fragment is empty, this causes an underflow in the unsigned size variable, resulting in a buffer overflow. The fix is simple: explicitly check if the string length is non-zero before subtracting.
Diffstat (limited to 'test/functional/legacy/normal_spec.lua')
0 files changed, 0 insertions, 0 deletions