Bug #22315
Updated by danielchong (Daniel Chong) 13 days ago
PoC: ``` s = "C" * 4000 s.unpack("L*") { s.clear } ``` Asan (truncated): ``` ERROR: AddressSanitizer: heap-use-after-free on address 0x... READ of size 4 ... thread T0 #3 bary_unpack_internal bignum.c:1179 #4 rb_integer_unpack bignum.c:3753 #5 pack_unpack_internal pack.c:1415 <-- USE 0x... is located 4 bytes inside of 4001-byte region [...] freed by thread T0 here: #2 ruby_xfree_sized gc.c:6295 #3 str_discard string.c:2840 #4 rb_str_clear string.c:6678 ... #16 rb_yield vm_eval.c #17 pack_unpack_internal pack.c:1416 <-- FREE (user block via rb_yield) ```