From: "rwstauner (Randy Stauner) via ruby-core" Date: 2026-09-28T20:42:56+00:00 Subject: [ruby-core:126871] [Ruby Bug#22387] str_shared_replace incorrectly recalculates termlen Issue #22387 has been reported by rwstauner (Randy Stauner). ---------------------------------------- Bug #22387: str_shared_replace incorrectly recalculates termlen https://bugs.ruby-lang.org/issues/22387 * Author: rwstauner (Randy Stauner) * Status: Open * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: REQUIRED ---------------------------------------- This ruby snippet crashes under ASan ```ruby s = ("\u{30AF}" * 7).encode("UTF-16LE").b s.force_encoding("UTF-16LE") s.encode!("UTF-8") # 21 bytes in a 22-byte malloc, capa now claims 22 s << "x" # fits, per capa, then NUL terminator written at [22] ``` str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy. We can just switch that to rb_enc_raw_set to fix. -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/