From 6122fdfee99ea5b603691d198cc01599cd3b0c17 Mon Sep 17 00:00:00 2001 From: "Yukihiro \"Matz\" Matsumoto" Date: Wed, 22 Oct 2025 22:47:39 +0900 Subject: [PATCH] string.c: guard memcmp() call to avoid undefined behavior with NULL pointers passing NULL pointers to memcmp() is undefined behavior per C standard, even when size is 0. memcmp() is declared with nonnull attributes, and ASAN can detect this violation. in mrb_str_cmp(), when comparing two empty strings or when the minimum length is 0, we now skip the memcmp() call and directly set retval to 0. this avoids the undefined behavior while maintaining correct comparison semantics. Co-authored-by: Claude --- src/string.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/src/string.c b/src/string.c index 9918b2903..88575c7ca 100644 --- a/src/string.c +++ b/src/string.c @@ -1200,7 +1200,16 @@ mrb_str_cmp(mrb_state *mrb, mrb_value str1, mrb_value str2) mrb_int len1 = RSTR_LEN(s1); mrb_int len2 = RSTR_LEN(s2); mrb_int len = lesser(len1, len2); - mrb_int retval = memcmp(RSTR_PTR(s1), RSTR_PTR(s2), len); + mrb_int retval; + + /* avoid UB: memcmp requires non-NULL pointers even when size is 0 */ + if (len == 0) { + retval = 0; + } + else { + retval = memcmp(RSTR_PTR(s1), RSTR_PTR(s2), len); + } + if (retval == 0) { if (len1 == len2) return 0; if (len1 > len2) return 1;