This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch misc-hardening__MATH-1691 in repository https://gitbox.apache.org/repos/asf/commons-math.git
commit da3d79c0d430ca989dd20dc7617f19cfb7324e7f Author: Gilles Sadowski <[email protected]> AuthorDate: Sun Sep 27 18:44:37 2026 +0200 MATH-1691: Abort early on non finite input. Found by a security scan. --- .../commons/math4/legacy/fitting/SimpleCurveFitter.java | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java b/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java index 012c913ef..6b5c03670 100644 --- a/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java +++ b/commons-math-legacy/src/main/java/org/apache/commons/math4/legacy/fitting/SimpleCurveFitter.java @@ -24,6 +24,7 @@ import java.util.ArrayList; import org.apache.commons.math4.legacy.exception.ZeroException; import org.apache.commons.math4.legacy.exception.OutOfRangeException; +import org.apache.commons.math4.legacy.exception.NotFiniteNumberException; import org.apache.commons.math4.legacy.analysis.ParametricUnivariateFunction; import org.apache.commons.math4.legacy.fitting.leastsquares.LeastSquaresBuilder; import org.apache.commons.math4.legacy.fitting.leastsquares.LeastSquaresProblem; @@ -134,8 +135,14 @@ public class SimpleCurveFitter extends AbstractCurveFitter { int count = 0; for (WeightedObservedPoint obs : observations) { - target[count] = obs.getY(); - weights[count] = obs.getWeight(); + final double v = obs.getY(); + final double w = obs.getWeight(); + + NotFiniteNumberException.check(v); + NotFiniteNumberException.check(w); + + target[count] = v; + weights[count] = w; ++count; } @@ -318,8 +325,8 @@ public class SimpleCurveFitter extends AbstractCurveFitter { private boolean isBetween(double value, double boundary1, double boundary2) { - return (value >= boundary1 && value <= boundary2) || - (value >= boundary2 && value <= boundary1); + return value >= boundary1 && value <= boundary2 || + value >= boundary2 && value <= boundary1; } } }
