Out-of-bounds read for corrupt view offsets in BaseVariableWidthViewVector
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
Research direction
Start in BaseVariableWidthViewVector and inspect the out-of-line view handling in getData, getDataPointer, hashCode, copyFromNotNull, and splitAndTransferViewBufferAndDataBuffer. Compare the linked pull request, then verify that corrupt buffer indexes and offset/length ranges no longer permit out-of-bounds reads, including with unsafe memory access enabled.
Written by the indexing model from the issue text.
Description
Describe the bug
ViewVarCharVector/ViewVarBinaryVector store values longer than INLINE_SIZE (12 bytes) out of line, encoding a data-buffer index and an offset inline in the view buffer. When a vector is loaded from an IPC stream these fields come straight from the input.
BaseVariableWidthViewVector dereferences them verbatim in getData, getDataPointer, hashCode, copyFromNotNull and splitAndTransferViewBufferAndDataBuffer, e.g.
dataBuffers.get(bufferIndex).getBytes(dataOffset, result, 0, dataLength);
Nothing checks that bufferIndex is in range or that dataOffset + dataLength fits inside the referenced data buffer. A crafted view whose offset/length points past the data buffer produces an out-of-bounds read: with the default bounds checking it throws IndexOutOfBoundsException, but with arrow.enable_unsafe_memory_access=true (commonly set in production) it reads arbitrary native heap into the returned value.
Component(s)
Java
- Dominant language
- Java
- Stars
- 95
- Forks
- 154
- Avg merge
- 2d 16h
- Merged PRs (30d)
- 9
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/arrow-java
-
Type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/arrow-java#1300 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
apache/arrow-java#1261 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/arrow-java#1236 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/arrow-java#1230 ·
-
Type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
apache/arrow-java#1205 ·
All issues in apache/arrow-java
Similar issues
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
apache/cloudstack#14222 ·
-
[BUG]茶杯方块在取茶时会引发崩溃 Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
1.0.0-alpha2 Type/Improvement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
wso2/dpdp-accelerator#272 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
infinispan/infinispan#18150 ·
-
area/frontend
Difficulty 2/5 1-3 hours Newbie friendliness 65/100