From b3c8f82681c2b1febd55b4a2a51175a20ded6452 Mon Sep 17 00:00:00 2001 From: Phil Phauler Date: Thu, 3 Sep 2026 14:20:43 +0200 Subject: [PATCH] Fix #2828, use PLATFORM bound for pool bucket array size check The NumBlockSizes validation in CFE_ES_PoolCreateEx_WithAlignment uses CFE_MISSION_ES_POOL_MAX_BUCKETS, but the actual Buckets array in CFE_ES_GenPoolRecord_t is sized to CFE_PLATFORM_ES_POOL_MAX_BUCKETS. When MISSION > PLATFORM (a valid, documented configuration), this allows NumBlockSizes values that overflow the array in GenPoolInitialize, corrupting adjacent entries in the global pool table. --- modules/es/fsw/src/cfe_es_mempool.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/es/fsw/src/cfe_es_mempool.c b/modules/es/fsw/src/cfe_es_mempool.c index 067da998b..ffd223245 100644 --- a/modules/es/fsw/src/cfe_es_mempool.c +++ b/modules/es/fsw/src/cfe_es_mempool.c @@ -227,12 +227,12 @@ CFE_Status_t CFE_ES_PoolCreateEx_WithAlignment(CFE_ES_MemHandle_t *PoolID, } /* If too many sizes are specified, return an error */ - if (NumBlockSizes > CFE_MISSION_ES_POOL_MAX_BUCKETS) + if (NumBlockSizes > CFE_PLATFORM_ES_POOL_MAX_BUCKETS) { CFE_ES_WriteToSysLog("%s: Num Block Sizes (%d) greater than max (%d)\n", __func__, (int)NumBlockSizes, - CFE_MISSION_ES_POOL_MAX_BUCKETS); + CFE_PLATFORM_ES_POOL_MAX_BUCKETS); return CFE_ES_BAD_ARGUMENT; }