Project

General

Profile

Actions

Bug #22319

closed

heap buffer overflow triggered by array's zip function

Bug #22319: heap buffer overflow triggered by array's zip function

Added by danielchong (Daniel Chong) 5 days ago. Updated about 21 hours ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:126731]

Description

Hi, I found a heap buffer overflow affecting array's zip functionality.

PoC:

a = (1..3000).to_a
evil = Object.new; $a = a
def evil.to_ary; $a.clear; [1,2,3]; end
a.zip(evil) 

ASAN output (truncated):
ERROR: AddressSanitizer: heap-buffer-overflow ... READ of size 8 ...
#0 RARRAY_AREF internal/array.h:153
#1 rb_ary_zip array.c:4850 <-- USE (stale len)
0x... is located 0 bytes after 256-byte region [...]
allocated by thread T0 here:
#4 ary_heap_realloc array.c:396
#5 ary_resize_capa array.c:439
#6 rb_ary_clear array.c:4988 <-- SHRINK (via arg's to_ary)
...
#18 convert_type_with_id object.c:3303 <-- take_items -> to_ary

Updated by peterzhu2118 (Peter Zhu) 5 days ago Actions #1 [ruby-core:126734]

  • Backport changed from 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN to 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED

Thank you for reporting this bug. I have a fix here and have requested backports to Ruby 3.4 and 4.0.

Updated by peterzhu2118 (Peter Zhu) 5 days ago Actions #2

  • Status changed from Open to Closed

Applied in changeset git|0c9f3f1e68e23a9ba2d7fdfdb86bd7ddcaf5e9d9.


Fix use-after-free when clearing array during zip

[Bug #22319]

Array#zip triggers an use-after-free it does not account for when the call
to rb_check_array_type modifies the source array. The following script crashes:

a = (1..100_000).to_a
evil = Object.new; $a = a
def evil.to_ary; $a.clear; [1,2,3]; end
a.zip(evil)

Updated by nagachika (Tomoyuki Chikanaga) about 21 hours ago ยท Edited Actions #3 [ruby-core:126797]

  • Backport changed from 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: DONE, 4.0: REQUIRED

Updated by nagachika (Tomoyuki Chikanaga) about 21 hours ago Actions #4

  • Backport changed from 3.3: WONTFIX, 3.4: DONE, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED

Updated by nagachika (Tomoyuki Chikanaga) about 21 hours ago Actions #5 [ruby-core:126804]

  • Backport changed from 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: DONE, 4.0: REQUIRED
Actions

Also available in: PDF Atom