Allocator call receives an unchecked `$N * sizeof($T)` byte count. If `$N` is large (e.g., attacker-controlled, derived from a model/file field), the multiplication can wrap `size_t` and the allocator will return an under-sized buffer while the caller still indexes up to `$N` elements, causing a heap buffer overflow (CWE-680, CVE-2025-54952). Guard the multi
Explore
Rule Explorer
Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.
- Public rules
- 4797
- Downloads
- 7.5M
- Verified
- 4797
- Authors
- 2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
CVE-2025-54952: Executorch Unchecked Size Mul Sizeof In Allocatecve-2025-54952-executorch-unchecked-size-mul-sizeof-in-allocate
CVE-2024-46952: Integer Truncation Max Width Allocationcve-2024-46952-integer-truncation-max-width-allocation
An integer truncation occurs when a 64-bit array element is assigned to a 32-bit integer. When this truncated value is subsequently used in a function call (such as a memory allocation size), it can result in allocating an undersized buffer, leading to an overflow. Ensure the variable is of an adequate type (e.g., `uint64_t`) and implement bounds checking on
All matching rules loaded.