Skip to content

fix: validate CFB mini streams and legacy sizes - #1041

Merged
andiwand merged 2 commits into
mainfrom
review/23-cfb-validation
Oct 5, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/23-cfb-validation

Conversation

@andiwand

@andiwand andiwand commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

CFB now checks the header's byte order, mini-sector size and cutoff, the root entry type, and directory-name length/termination. Mini-sector reads must stay inside the root mini stream, not merely inside the containing file. Empty reads do not traverse sector chains.

For version 3 files, ignore the high size DWORD as required for older writers by MS-CFB 2.6.1. Version 4 entry sizes are checked before narrowing to size_t.

Validation: 40 CFB, legacy Office, OOXML crypto, and document-file tests pass. Synthetic fixtures cover malformed headers/names, legacy size words, and invalid mini-sector references. Rules checked against vendored MS-CFB sections 2.2, 2.4, and 2.6.1.

@andiwand
andiwand force-pushed the review/22-archive-metadata branch from cdcec94 to 84f1751 Compare October 5, 2026 07:02
Base automatically changed from review/22-archive-metadata to main October 5, 2026 07:04
@andiwand
andiwand force-pushed the review/23-cfb-validation branch from f7ae468 to f5744fe Compare October 5, 2026 07:08
@andiwand
andiwand merged commit 9ca35d4 into main Oct 5, 2026
23 checks passed
@andiwand
andiwand deleted the review/23-cfb-validation branch October 5, 2026 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant