Skip to content

Commit 4feb2b2

Browse files
Fix invalid UTF-8 handling in SQLite parser
Port gwenn/lemon-rs@14f422a to replace the unchecked UTF-8 conversion with a lossy conversion. Bump the vendored parser to 0.13.1 and add regression coverage for invalid input.\n\nAddresses CVE-2025-47736 / GHSA-8m95-fffc-h4c5.
1 parent cc4e8a6 commit 4feb2b2

3 files changed

Lines changed: 13 additions & 3 deletions

File tree

‎Cargo.lock‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎vendored/sqlite3-parser/Cargo.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
[package]
22
name = "libsql-sqlite3-parser"
3-
version = "0.13.0"
3+
version = "0.13.1"
44
edition = "2021"
55
authors = ["gwenn"]
66
description = "SQL parser (as understood by SQLite) (libsql fork)"

‎vendored/sqlite3-parser/src/dialect/mod.rs‎

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ impl TokenType {
5858
}
5959

6060
fn from_bytes(bytes: &[u8]) -> String {
61-
unsafe { str::from_utf8_unchecked(bytes).to_owned() }
61+
String::from_utf8_lossy(bytes).to_string()
6262
}
6363

6464
include!(concat!(env!("OUT_DIR"), "/keywords.rs"));
@@ -403,3 +403,13 @@ impl TokenType {
403403
}
404404
}
405405
}
406+
407+
#[cfg(test)]
408+
mod tests {
409+
use super::from_bytes;
410+
411+
#[test]
412+
fn converts_invalid_utf8_lossily() {
413+
assert_eq!(from_bytes(&[0xC0, 0x80]), "��");
414+
}
415+
}

0 commit comments

Comments
 (0)