CVE-2026-58472: Loop Accumulation Integer Overflow Allocation

Accumulating buffer sizes in a loop using `+` or `+=` without overflow checks can lead to integer overflow. If the result is passed to an allocator, an undersized buffer is created, leading to a heap buffer overflow. Use sizes like `size_t` and safe integer arithmetic constructs like `INT_ADD_OK` to prevent overflow.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-58472-loop-accumulation-integer-overflow-allocation --engine opengrep

Description

Accumulating buffer sizes in a loop using `+` or `+=` without overflow checks can lead to integer overflow. If the result is passed to an allocator, an undersized buffer is created, leading to a heap buffer overflow. Use sizes like `size_t` and safe integer arithmetic constructs like `INT_ADD_OK` to prevent overflow.