Skip to content

[FIX] Prevent infinite loop parsing when record has a corrupted size#288

Merged
omerbenamram merged 1 commit intoomerbenamram:masterfrom
maxspl:master
Mar 21, 2026
Merged

[FIX] Prevent infinite loop parsing when record has a corrupted size#288
omerbenamram merged 1 commit intoomerbenamram:masterfrom
maxspl:master

Conversation

@maxspl
Copy link
Copy Markdown
Contributor

@maxspl maxspl commented Mar 16, 2026

Hi,

I've encountered an issue with evtx records that have a corrupted data_size field. This causes an infinite loop.

I can't provide the evtx records, but here is the debug output:

09:47:09 [INFO] Record id - 0
09:47:09 [DEBUG] (14) evtx::evtx_chunk: Record header - EvtxRecordHeader { data_size: 3099113656, event_record_id: 0, timestamp: 1601-01-01T00:00:00Z }
09:47:09 [INFO] Record id - 0
09:47:09 [DEBUG] (14) evtx::evtx_chunk: Record header - EvtxRecordHeader { data_size: 3099113656, event_record_id: 0, timestamp: 1601-01-01T00:00:00Z }
09:47:09 [INFO] Record id - 0
09:47:09 [DEBUG] (14) evtx::evtx_chunk: Record header - EvtxRecordHeader { data_size: 3099113656, event_record_id: 0, timestamp: 1601-01-01T00:00:00Z }
09:47:09 [INFO] Record id - 0

The fix allows skipping the chunk and exiting the infinite loop.

Thanks in advance :)

@omerbenamram omerbenamram merged commit 9117c21 into omerbenamram:master Mar 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants