Fixed crash with invalid value of 'guicursor' #1465
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Vim-8.0.325 and older crashes with this command:
Beware: the command not only crashes Vim but also freezes my computer
for several seconds, as Vim allocates a huge amount of memory.
Address sanitizer gives this error:
Code at misc2.c:
At line 3635, (end - p) is negative, which causes to allocate a negative
number of bytes i.e. a huge number of bytes in vim_strsave().
At misc2.c, we have:
Bug was found using afl-fuzz.
This PR fixes the bug and adds tests which triggers the crash prior to the fix.