From 79047e83f2945513e1a7cca39be4b9bf016b3f81 Mon Sep 17 00:00:00 2001 From: stijncarelsbergh Date: Thu, 8 Oct 2026 00:04:22 +0200 Subject: [PATCH] fix(commander): guard the fixed-size callback arrays in add() call_list/call_ids/call_label hold 20 entries and call_count was never checked, so the 21st add() writes a function pointer, a char and a pointer past the end of the object - out-of-bounds write, memory corruption, symptoms depending on layout. --- src/communication/Commander.cpp | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/communication/Commander.cpp b/src/communication/Commander.cpp index 1ddded8fe..5b3cf5f8d 100644 --- a/src/communication/Commander.cpp +++ b/src/communication/Commander.cpp @@ -12,6 +12,8 @@ Commander::Commander(char eol, bool echo){ void Commander::add(char id, CommandCallback onCommand, const char* label ){ + // guard the fixed-size callback arrays (call_list/call_ids/call_label) + if (call_count >= (int)(sizeof(call_list) / sizeof(call_list[0]))) return; call_list[call_count] = onCommand; call_ids[call_count] = id; call_label[call_count] = (char*)label;