Bug 1466

Summary: Dereferencing a null pointer for zero sized matrices
Product: Eigen Reporter: Mmanu Chaturvedi <mmanu.chaturvedi>
Component: Core - matrix productsAssignee: Nobody <eigen.nobody>
Status: CONFIRMED ---    
Severity: Unknown CC: chtz, gael.guennebaud
Priority: Normal    
Version: 3.3 (current stable)   
Hardware: x86 - 64-bit   
OS: Linux   

Description Mmanu Chaturvedi 2017-09-14 16:17:46 UTC
If my assumption that Eigen allows multiplying zero sized matrices on purpose is correct, then there is a dereferencing of null pointer happening which seems benign to start with, but I'm not sure if it always so because the function getVectorMapper causing the trouble is used at other places as well.

To reproduce, here's the code (to be run with UBSan) :

I say benign because all the usages of lhs0 variable which is calling the function dereferencing a null pointer (BlasUtil.h:218 via BlasUtil.h:211 in version 3.3.3) are conditional and never run for zero sized matrices:

I observed that the bug is not reproducible with the current default, perhaps because GeneralMatrixVector.h was totally revamped, but is reproducible with 3.3.4.
Comment 1 Christoph Hertzberg 2017-09-14 17:42:19 UTC
I can confirm this. In the devel branch it has been fixed within this commit (and the following "fix" commit):
