Description
This is an attempt to write outside an array or buffer’s valid range. Ordinary Java arrays check bounds at runtime: an invalid index throws ArrayIndexOutOfBoundsException and the assignment is not performed. Distinguish this from memory corruption in native code or unsafe memory APIs.
Potential impact
- Interrupted processing: An unhandled exception may cause a request or task to fail.
- Partial state changes: Changes made before the exception may remain, so review error handling and transaction boundaries.
Remediation
- Before writing, require the index to be at least
0and less than the array length. - Return a clear error for invalid input. Do not treat the occurrence of an exception as a substitute for input validation.
- If input controls a copy length or starting position, validate the resulting range as well.
Examples
Before
These controller excerpts demonstrate bounds checking only. A new array is created on every call; no persistent store is updated. Map invalid-input exceptions to an appropriate client-error response.
java
@GetMapping("/update")
public void updateData(@RequestParam int index, @RequestParam int value) {
int[] data = new int[10];
data[index] = value; // No bounds check
}
After
java
@GetMapping("/update")
public void updateData(@RequestParam int index, @RequestParam int value) {
int[] data = new int[10];
if (index >= 0 && index < data.length) {
data[index] = value; // Bounds checked
} else {
throw new IllegalArgumentException("Invalid index");
}
}
Explanation:
- Before: Does not validate
index, so an out-of-range value throwsArrayIndexOutOfBoundsException. This Java array assignment does not corrupt memory outside the array. - After: Accepts only an index within the array and rejects other values with
IllegalArgumentException.
Related CVEs
The following cases concern memory writes on other platforms. They do not imply the same memory corruption occurs in the Java array example above.
- CVE-2023-1017: The reference implementation code for a Trusted Platform Module does not implement length checks on data, allowing for an attacker to write 2 bytes past the end of a buffer.
- CVE-2021-21220: Chain: insufficient input validation (CWE-20) in browser allows heap corruption (CWE-787), as exploited in the wild per CISA KEV.
- CVE-2021-28664: GPU kernel driver allows memory corruption because a user can obtain read/write access to read-only pages, as exploited in the wild per CISA KEV.