diff --git a/server/conn_stmt.go b/server/conn_stmt.go index 97fbca02e3..9314c4b19c 100644 --- a/server/conn_stmt.go +++ b/server/conn_stmt.go @@ -185,6 +185,10 @@ func parseStmtArgs(args []interface{}, boundParams [][]byte, nullBitmap, paramTy continue } + if (i<<1)+1 >= len(paramTypes) { + return mysql.ErrMalformPacket + } + tp := paramTypes[i<<1] isUnsigned := (paramTypes[(i<<1)+1] & 0x80) > 0