Actions
Bug #22315
closedheap-use-after-free in String unpack with a block that mutates the receiver
Bug #22315:
heap-use-after-free in String unpack with a block that mutates the receiver
Description
PoC:
Asan (truncated):
ERROR: AddressSanitizer: heap-use-after-free on address 0x...
READ of size 4 ... thread T0
#3 bary_unpack_internal bignum.c:1179
#4 rb_integer_unpack bignum.c:3753
#5 pack_unpack_internal pack.c:1415 <-- USE
0x... is located 4 bytes inside of 4001-byte region [...]
freed by thread T0 here:
#2 ruby_xfree_sized gc.c:6295
#3 str_discard string.c:2840
#4 rb_str_clear string.c:6678
...
#16 rb_yield vm_eval.c
#17 pack_unpack_internal pack.c:1416 <-- FREE (user block via rb_yield)
Updated by danielchong (Daniel Chong) 6 days ago
- Description updated (diff)
Updated by peterzhu2118 (Peter Zhu) 6 days ago
- Backport changed from 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN to 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED
Thank you for the bug report. I was able to reproduce this issue under ASAN and able to trigger a crash even without ASAN by increasing the size of the string s. I have a fix here and I've requested backports for Ruby 3.4 and 4.0.
Updated by peterzhu2118 (Peter Zhu) 5 days ago
- Status changed from Open to Closed
Applied in changeset git|685144e3d60513ccde1c6cb4bed20597cb860002.
Fix crash when source string modified in String#unpack
[Bug #22315]
The following script crashes because there is a use-after-free on the
source string during String#unpack:
String#unpack will now instead raise RuntimeError with message "string modified".
Updated by nagachika (Tomoyuki Chikanaga) about 21 hours ago
ยท Edited
- Backport changed from 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: DONE, 4.0: REQUIRED
Updated by nagachika (Tomoyuki Chikanaga) about 21 hours ago
ruby_3_4 ce5cca10a5143da2ccea33a53190e39a6b923241 merged revision(s) 685144e3d60513ccde1c6cb4bed20597cb860002.
Actions