fix out-of-bounds read in mime_check_rules char test#1614
Open
aizu-m wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Caught this with AddressSanitizer while fuzzing type detection on short files:
Traced it back to the
char()magic test. Every other fixed-offset op (string,istring,short,int,contains) reloads the file buffer when(rules->offset + N) > (fb->offset + fb->length). TheMIME_MAGIC_CHARcase only checksrules->offset < fb->offset, so a rule whose offset sits past the buffered region never triggers a reload andfb->buffer[rules->offset - fb->offset]reads past the data.mimeFileType only buffers the first 8192 bytes, so a
char()rule at a large offset against a short file walks straight off the stack buffer. Minimal repro: type a 1-byte file againstchar(100000,65)and it segfaults at type.c:913. With the offset term added the read stays in range and the test just returns no-match.Lined the condition up with the sibling cases.