[PR #527] fix: segfault: scatter series with no categories, when the ranges are set with chart_series_set #526

Open
opened 2026-10-02 23:12:49 -06:00 by gitea-mirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/jmcnamara/libxlsxwriter/pull/527
Author: @PGZXB
Created: 9/24/2026
Status: 🔄 Open

Base: main ← Head: fix-issue-525


📝 Commits (1)

  • 03e9e09 fix: segfault: scatter series with no categories, when the ranges are set with chart_series_set (#525)

📊 Changes

2 files changed (+18 additions, -0 deletions)

View changed files

📝 src/chartsheet.c (+9 -0)
📝 src/worksheet.c (+9 -0)

📄 Description

Fixes #525

Fixes the memory-safety issue reported in #525: Segfault: scatter series with no categories, when the ranges are set with chart_series_set_values().

Fix

Adds the missing bounds/validity check at the faulting site.

diff --git a/src/chartsheet.c b/src/chartsheet.c
index 0848bcf..eaef19c 100644
--- a/src/chartsheet.c
+++ b/src/chartsheet.c
@@ -259,6 +259,15 @@ chartsheet_set_chart_opt(lxw_chartsheet *self,
 
             return LXW_ERROR_PARAMETER_VALIDATION;
         }
+
+        if (chart->chart_group == LXW_CHART_SCATTER
+            && !series->categories->formula
+            && !series->categories->sheetname) {
+            LXW_WARN("chartsheet_set_chart()/_opt(): scatter charts must "
+                     "have a 'categories' series.");
+
+            return LXW_ERROR_PARAMETER_VALIDATION;
+        }
     }
 
     /* Create a new object to hold the chart image properties. */
diff --git a/src/worksheet.c b/src/worksheet.c
index 3a30007..418f8b6 100644
--- a/src/worksheet.c
+++ b/src/worksheet.c
@@ -11092,6 +11092,15 @@ worksheet_insert_chart_opt(lxw_worksheet *self,
 
             return LXW_ERROR_PARAMETER_VALIDATION;
         }
+
+        if (chart->chart_group == LXW_CHART_SCATTER
+            && !series->categories->formula
+            && !series->categories->sheetname) {
+            LXW_WARN("worksheet_insert_chart()/_opt(): scatter charts must "
+                     "have a 'categories' series.");
+
+            return LXW_ERROR_PARAMETER_VALIDATION;
+        }
     }
 
     /* Create a new object to hold the chart image properties. */

Verification Before Fix

'all'.
make[1]: Leaving directory '/src/libxlsxwriter/third_party/minizip'
make[1]: Entering directory '/src/libxlsxwriter/third_party/tmpfileplus'
make[1]: Nothing to be done for 'all'.
make[1]: Leaving directory '/src/libxlsxwriter/third_party/tmpfileplus'
make[1]: Entering directory '/src/libxlsxwriter/third_party/md5'
make[1]: Nothing to be done for 'all'.
make[1]: Leaving directory '/src/libxlsxwriter/third_party/md5'
make[1]: Entering directory '/src/libxlsxwriter/src'
make[1]: Leaving directory '/src/libxlsxwriter/src'
LIB=/src/libxlsxwriter/lib/libxlsxwriter.a
BUILD_SANDBOX_DONE
AddressSanitizer:DEADLYSIGNAL
=================================================================
==36==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7f6076641f58 bp 0x7ffeef1133a0 sp 0x7ffeef112b58 T0)
==36==The signal is caused by a READ memory access.
==36==Hint: address points to the zero page.
    #0 0x7f6076641f58  (/lib/x86_64-linux-gnu/libc.so.6+0x1aaf58) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65)
    #1 0x55acd3547361 in strpbrk (/new_issue/poc_driver+0x6d361) (BuildId: a0eeea1c528c751fa34d1a72f6932a053965f9ed)
    #2 0x55acd36c0276 in _fprint_escaped_data /src/libxlsxwriter/src/xmlwriter.c:403:10
    #3 0x55acd36bf42f in lxw_xml_data_element /src/libxlsxwriter/src/xmlwriter.c:141:5
    #4 0x55acd361088c in _chart_write_f /src/libxlsxwriter/src/chart.c:1332:5
    #5 0x55acd361153e in _chart_write_num_ref /src/libxlsxwriter/src/chart.c:1457:5
    #6 0x55acd3611759 in _chart_write_data_cache /src/libxlsxwriter/src/chart.c:1499:9
    #7 0x55acd36224ec in _chart_write_x_val /src/libxlsxwriter/src/chart.c:3161:5
    #8 0x55acd3622bf8 in _chart_write_xval_ser /src/libxlsxwriter/src/chart.c:3289:5
    #9 0x55acd362f2ff in _chart_write_scatter_chart /src/libxlsxwriter/src/chart.c:4818:9
    #10 0x55acd362f872 in _chart_write_scatter_plot_area /src/libxlsxwriter/src/chart.c:4876:5
    #11 0x55acd362fdc8 in _chart_write_chart /src/libxlsxwriter/src/chart.c:4962:5
    #12 0x55acd363181b in lxw_chart_assemble_xml_file /src/libxlsxwriter/src/chart.c:5274:5
    #13 0x55acd36d34f9 in _write_chart_files /src/libxlsxwriter/src/packager.c:540:9
    #14 0x55acd36df0a6 in lxw_create_package /src/libxlsxwriter/src/packager.c:2187:13
    #15 0x55acd365896d in workbook_close /src/libxlsxwriter/src/workbook.c:2306:13
    #16 0x55acd3604b07 in main /new_issue/poc/lxw_scatter_segfault.c:190:42
    #17 0x7f60764c11c9  (/lib/x86_64-linux-gnu/libc.so.6+0x2a1c9) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65)
    #18 0x7f60764c128a in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28a) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65)
    #19 0x55acd352b4b4 in _start (/new_issue/poc_driver+0x514b4) (BuildId: a0eeea1c528c751fa34d1a72f6932a053965f9ed)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV (/lib/x86_64-linux-gnu/libc.so.6+0x1aaf58) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65) 
==36==ABORTING

Verification After Fix

[WARNING]: worksheet_insert_chart()/_opt(): scatter charts must have a 'categories' series.
  workbook_close() -> 0


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/jmcnamara/libxlsxwriter/pull/527 **Author:** [@PGZXB](https://github.com/PGZXB) **Created:** 9/24/2026 **Status:** 🔄 Open **Base:** `main` ← **Head:** `fix-issue-525` --- ### 📝 Commits (1) - [`03e9e09`](https://github.com/jmcnamara/libxlsxwriter/commit/03e9e098c4c10755e703e46601ab9d9794f6fa76) fix: segfault: scatter series with no categories, when the ranges are set with chart_series_set (#525) ### 📊 Changes **2 files changed** (+18 additions, -0 deletions) <details> <summary>View changed files</summary> 📝 `src/chartsheet.c` (+9 -0) 📝 `src/worksheet.c` (+9 -0) </details> ### 📄 Description Fixes #525 Fixes the memory-safety issue reported in #525: Segfault: scatter series with no categories, when the ranges are set with chart_series_set_values(). ## Fix Adds the missing bounds/validity check at the faulting site. ```diff diff --git a/src/chartsheet.c b/src/chartsheet.c index 0848bcf..eaef19c 100644 --- a/src/chartsheet.c +++ b/src/chartsheet.c @@ -259,6 +259,15 @@ chartsheet_set_chart_opt(lxw_chartsheet *self, return LXW_ERROR_PARAMETER_VALIDATION; } + + if (chart->chart_group == LXW_CHART_SCATTER + && !series->categories->formula + && !series->categories->sheetname) { + LXW_WARN("chartsheet_set_chart()/_opt(): scatter charts must " + "have a 'categories' series."); + + return LXW_ERROR_PARAMETER_VALIDATION; + } } /* Create a new object to hold the chart image properties. */ diff --git a/src/worksheet.c b/src/worksheet.c index 3a30007..418f8b6 100644 --- a/src/worksheet.c +++ b/src/worksheet.c @@ -11092,6 +11092,15 @@ worksheet_insert_chart_opt(lxw_worksheet *self, return LXW_ERROR_PARAMETER_VALIDATION; } + + if (chart->chart_group == LXW_CHART_SCATTER + && !series->categories->formula + && !series->categories->sheetname) { + LXW_WARN("worksheet_insert_chart()/_opt(): scatter charts must " + "have a 'categories' series."); + + return LXW_ERROR_PARAMETER_VALIDATION; + } } /* Create a new object to hold the chart image properties. */ ``` ## Verification Before Fix ``` 'all'. make[1]: Leaving directory '/src/libxlsxwriter/third_party/minizip' make[1]: Entering directory '/src/libxlsxwriter/third_party/tmpfileplus' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/src/libxlsxwriter/third_party/tmpfileplus' make[1]: Entering directory '/src/libxlsxwriter/third_party/md5' make[1]: Nothing to be done for 'all'. make[1]: Leaving directory '/src/libxlsxwriter/third_party/md5' make[1]: Entering directory '/src/libxlsxwriter/src' make[1]: Leaving directory '/src/libxlsxwriter/src' LIB=/src/libxlsxwriter/lib/libxlsxwriter.a BUILD_SANDBOX_DONE AddressSanitizer:DEADLYSIGNAL ================================================================= ==36==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7f6076641f58 bp 0x7ffeef1133a0 sp 0x7ffeef112b58 T0) ==36==The signal is caused by a READ memory access. ==36==Hint: address points to the zero page. #0 0x7f6076641f58 (/lib/x86_64-linux-gnu/libc.so.6+0x1aaf58) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65) #1 0x55acd3547361 in strpbrk (/new_issue/poc_driver+0x6d361) (BuildId: a0eeea1c528c751fa34d1a72f6932a053965f9ed) #2 0x55acd36c0276 in _fprint_escaped_data /src/libxlsxwriter/src/xmlwriter.c:403:10 #3 0x55acd36bf42f in lxw_xml_data_element /src/libxlsxwriter/src/xmlwriter.c:141:5 #4 0x55acd361088c in _chart_write_f /src/libxlsxwriter/src/chart.c:1332:5 #5 0x55acd361153e in _chart_write_num_ref /src/libxlsxwriter/src/chart.c:1457:5 #6 0x55acd3611759 in _chart_write_data_cache /src/libxlsxwriter/src/chart.c:1499:9 #7 0x55acd36224ec in _chart_write_x_val /src/libxlsxwriter/src/chart.c:3161:5 #8 0x55acd3622bf8 in _chart_write_xval_ser /src/libxlsxwriter/src/chart.c:3289:5 #9 0x55acd362f2ff in _chart_write_scatter_chart /src/libxlsxwriter/src/chart.c:4818:9 #10 0x55acd362f872 in _chart_write_scatter_plot_area /src/libxlsxwriter/src/chart.c:4876:5 #11 0x55acd362fdc8 in _chart_write_chart /src/libxlsxwriter/src/chart.c:4962:5 #12 0x55acd363181b in lxw_chart_assemble_xml_file /src/libxlsxwriter/src/chart.c:5274:5 #13 0x55acd36d34f9 in _write_chart_files /src/libxlsxwriter/src/packager.c:540:9 #14 0x55acd36df0a6 in lxw_create_package /src/libxlsxwriter/src/packager.c:2187:13 #15 0x55acd365896d in workbook_close /src/libxlsxwriter/src/workbook.c:2306:13 #16 0x55acd3604b07 in main /new_issue/poc/lxw_scatter_segfault.c:190:42 #17 0x7f60764c11c9 (/lib/x86_64-linux-gnu/libc.so.6+0x2a1c9) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65) #18 0x7f60764c128a in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28a) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65) #19 0x55acd352b4b4 in _start (/new_issue/poc_driver+0x514b4) (BuildId: a0eeea1c528c751fa34d1a72f6932a053965f9ed) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV (/lib/x86_64-linux-gnu/libc.so.6+0x1aaf58) (BuildId: a4a7992a8e66555c8141ab2a08a8465ff6e0ea65) ==36==ABORTING ``` ## Verification After Fix ``` [WARNING]: worksheet_insert_chart()/_opt(): scatter charts must have a 'categories' series. workbook_close() -> 0 ``` --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
github-starred/libxlsxwriter#526
No description provided.