Reject invalid DEFLATE HLIT values (GH #1368, PR #1371)
Inflator::DecodeHeader() accepted HLIT values 30 and 31, although RFC 1951 limits the field to 0 through 29. With HLIT and HDIST both set to 31, the declared code-length total reaches 320 entries against a 318-entry table. The repeat-run guard checked only against that declared total, allowing an out-of-bounds write. HDIST values 30 and 31 remain valid. RFC 1951 permits all 32 distance code lengths, and CreateFixedDistanceDecoder() initialises all 32 entries. Reject invalid HLIT values before filling the table and bound repeat runs against both the declared total and the table capacity.
C
CoraleSoft committed
21d16a32b099c00e94564f27b9cbe94398fa96c4
Parent: fe62c6a
Committed by GitHub <noreply@github.com>
on 8/4/2026, 3:06:47 PM