Executive brief
flatcc is a FlatBuffers compiler for C that translates schema files into C code. When a user accidentally declares the same table member twice in a schema file, the compiler crashes with an assertion error instead of reporting a proper syntax error. This denial-of-service vulnerability could disrupt development workflows and CI/CD pipelines that rely on flatcc for code generation.
Technical details
The vulnerability is a reachable assertion (CWE-617) in the align_order_members() function at src/compiler/semantics.c:1059. When a table member is declared twice, the duplicate entry's computed sort_key value collapses to 0, triggering the assertion `assert(k > 0)` and aborting the compiler with SIGABRT. The root cause is insufficient validation during semantic analysis; duplicate member names should be caught as redefinition errors before the ordering phase. The attack vector is attacker-controlled .fbs schema text, requiring no authentication or network access. A fix is available in commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205.
Affected products
- Dvidelabs flatcc up to 0.6.3
Timeline
- 2026-09-14: disclosed
- 2026-08-04: other: Bug report filed on GitHub issue #387
- other: Patch available: commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205