Project

General

Profile

Bug #22315

Updated by danielchong (Daniel Chong) 13 days ago

PoC: 
 ``` 
 s = "C" * 4000 
 s.unpack("L*") { s.clear } 
 ``` 

 Asan (truncated): 
 ``` 
 ERROR: AddressSanitizer: heap-use-after-free on address 0x...  
 READ of size 4 ... thread T0 
     #3 bary_unpack_internal     bignum.c:1179 
     #4 rb_integer_unpack        bignum.c:3753 
     #5 pack_unpack_internal     pack.c:1415          <-- USE 
 0x... is located 4 bytes inside of 4001-byte region [...] 
 freed by thread T0 here: 
     #2 ruby_xfree_sized         gc.c:6295 
     #3 str_discard              string.c:2840 
     #4 rb_str_clear             string.c:6678 
     ... 
     #16 rb_yield                vm_eval.c 
     #17 pack_unpack_internal    pack.c:1416           <-- FREE (user block via rb_yield) 
 ``` 


Back