Excessive memory allocation from user input

Excessive memory allocation from user input

Description

Using an unvalidated input size with make, bytes.Repeat, or strings.Repeat can allocate excessive memory.

Potential impact

  • Memory exhaustion or runtime panics may deny service.
  • A small request may trigger large resource consumption.

Remediation

  • Check that the size parses successfully and is between zero and the allowed maximum before allocating.
  • Set separate limits for request bodies, uploads, and repetition counts.

Examples

Before

go
size, _ := strconv.Atoi(r.FormValue("n"))
buf := make([]byte, size)

After

go
size, err := strconv.Atoi(r.FormValue("n"))
if err != nil || size < 0 || size > 4096 {
    return nil
}
buf := make([]byte, size)

Explanation:

  • Before: An attacker can supply a large size to make or a repetition-based allocation API and exhaust memory.
  • After: Reject invalid or out-of-range sizes before allocation.

References