Skip to content

[C++] Fix NULL pointer dereference in reflection VerifyVector() (union vector, CWE-476) - #9228

Open
thinhnallf wants to merge 2 commits into
google:masterfrom
thinhnallf:fix-verifyvector-union-nullptr-deref
Open

[C++] Fix NULL pointer dereference in reflection VerifyVector() (union vector, CWE-476)#9228
thinhnallf wants to merge 2 commits into
google:masterfrom
thinhnallf:fix-verifyvector-union-nullptr-deref

Conversation

@thinhnallf

@thinhnallf thinhnallf commented Sep 6, 2026

Copy link
Copy Markdown

Bug

In src/reflection.cpp, the reflection::Union case inside VerifyVector() can encounter a null pointer dereference if type_vec is null.

auto type_vec = table.GetPointer<Vector<uint8_t>*>(vec_field.offset() - sizeof(voffset_t));
if (!v.VerifyVector(type_vec)) return false; 
if (type_vec->size() != vec->size()) return false;  // NULL DEREF if type_vec is null

Since VerifierTemplate::VerifyVector(nullptr) intentionally returns true (as a null vector represents a valid, absent optional field), a null type_vec safely passes the verification line but subsequently causes an unconditional null pointer dereference during the size comparison.

Fix

Add an explicit null-check for type_vec immediately after the verification check, before it is dereferenced.

Testing

Confirmed locally that handling an absent companion type-vector field no longer causes a crash and is now correctly rejected by returning false.

…n vector, CWE-476)

VerifyVector()'s reflection::Union case can dereference a NULL type_vec
pointer when a FlatBuffer's vtable has the union value-vector field
present but the (implicit) companion type-vector field's slot absent.

VerifierTemplate::VerifyVector(nullptr) intentionally returns true
(a null vector is a valid, absent optional field), so a null type_vec
is not rejected by the existing VerifyVector(type_vec) check, and the
very next line dereferenced it unconditionally.

Related to, but distinct from, google#8567 (already fixed): that issue was
about a length mismatch between two non-null vectors; its fix added
the size comparison seen here but never added a null-check for
type_vec itself.
@github-actions github-actions Bot added c++ codegen Involving generating code from schema labels Sep 6, 2026
@google-cla

google-cla Bot commented Sep 6, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@thinhnallf

Copy link
Copy Markdown
Author

@googlebot check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++ codegen Involving generating code from schema

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant