Out-of-bounds write

Out-of-bounds write

Description

This is an attempt to write outside an array or buffer’s valid range. Ordinary Java arrays check bounds at runtime: an invalid index throws ArrayIndexOutOfBoundsException and the assignment is not performed. Distinguish this from memory corruption in native code or unsafe memory APIs.

Potential impact

  • Interrupted processing: An unhandled exception may cause a request or task to fail.
  • Partial state changes: Changes made before the exception may remain, so review error handling and transaction boundaries.

Remediation

  1. Before writing, require the index to be at least 0 and less than the array length.
  2. Return a clear error for invalid input. Do not treat the occurrence of an exception as a substitute for input validation.
  3. If input controls a copy length or starting position, validate the resulting range as well.

Examples

Before

These controller excerpts demonstrate bounds checking only. A new array is created on every call; no persistent store is updated. Map invalid-input exceptions to an appropriate client-error response.

java
@GetMapping("/update")
public void updateData(@RequestParam int index, @RequestParam int value) {
    int[] data = new int[10];
    data[index] = value; // No bounds check
}

After

java
@GetMapping("/update")
public void updateData(@RequestParam int index, @RequestParam int value) {
    int[] data = new int[10];
    if (index >= 0 && index < data.length) {
        data[index] = value; // Bounds checked
    } else {
        throw new IllegalArgumentException("Invalid index");
    }
}

Explanation:

  • Before: Does not validate index, so an out-of-range value throws ArrayIndexOutOfBoundsException. This Java array assignment does not corrupt memory outside the array.
  • After: Accepts only an index within the array and rejects other values with IllegalArgumentException.

Related CVEs

The following cases concern memory writes on other platforms. They do not imply the same memory corruption occurs in the Java array example above.

References