SEGV has occurred in function cJSONUtils_ApplyPatchesCaseSensitive at cJSON_Utils.c
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 48/100
Línea de trabajo
Comienza con cJSON_Utils.c en cJSONUtils_ApplyPatchesCaseSensitive y luego sigue los frames apply_patch y detach_path mencionados en el trace de ASan. Construye el reproductor mínimo en C con clang y AddressSanitizer, ejecútalo contra el POC enlazado y confirma que la entrada ya no provoca la condición SEGV o DoS indicada.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description
SEGV has occurred in function cJSONUtils_ApplyPatchesCaseSensitive at cJSON_Utils.c:1085
Version
commit c859b25da02955fef659d658b8f324b5cde87be3 (HEAD -> master, tag: v1.7.19, origin/master, origin/HEAD)
Author: Alan Wang <[email protected]>
Date: Tue Sep 9 21:56:10 2025 +0800
Release 1.7.19 (#958)
Steps to reproduce
The Crash can be reproduced with the following minimal c code
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include "cJSON.h"
#include "cJSON_Utils.h"
int main(int argc, char** argv) {
if (argc < 2) return 0;
unsigned char* data = NULL;
size_t size = 0;
FILE* fp = fopen(argv[1], "rb");
if (!fp) return 0;
fseek(fp, 0, SEEK_END);
size = ftell(fp);
fseek(fp, 0, SEEK_SET);
data = (unsigned char*)malloc(size + 1);
if (!data) { fclose(fp); return 0; }
if (fread(data, 1, size, fp) != size) { free(data); fclose(fp); return 0; }
data[size] = '\0';
fclose(fp);
cJSON* obj_1 = cJSON_CreateObject();
cJSON* obj_2 = cJSON_Parse(data);
if (obj_1 && obj_2) {
cJSONUtils_ApplyPatchesCaseSensitive(obj_1, obj_2);
}
if (obj_1) cJSON_Delete(obj_1);
if (obj_2) cJSON_Delete(obj_2);
free(data);
return 0;
}
$ https://github.com/DaveGamble/cJSON; cd cJSON.
$ clang -fsanitize=address -O0 -g -o minimize ./minimize.c cJSON.c cJSON_Utils.c
$ ./minimize poc-ApplyPatchesCaseSensitive-SEGV
=================================================================
==544063==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x757b239b213c bp 0x7ffc00685a30 sp 0x7ffc006851e8 T0)
==544063==The signal is caused by a READ memory access.
==544063==Hint: address points to the zero page.
#0 0x757b239b213c string/../sysdeps/x86_64/multiarch/strlen-evex.S:77
#1 0x5584c61d7489 in strlen (/Data/du4t/harnessGeneration/testcase/cJSON/5-CVE+0x36489) (BuildId: 675a8db95ab4b2105e92973333a1dd1eccdabf1b)
#2 0x5584c629b059 in cJSONUtils_strdup /cJSON/cJSON_Utils.c:71:14
#3 0x5584c629b059 in detach_path /cJSON/cJSON_Utils.c:438:22
#4 0x5584c62973db in apply_patch /cJSON/cJSON_Utils.c:918:21
#5 0x5584c6297e3f in cJSONUtils_ApplyPatchesCaseSensitive /cJSON/cJSON_Utils.c:1085:18
#6 0x5584c62800d0 in main cJSON/minimize.c:30:9
#7 0x757b23829d8f in __libc_start_call_main csu/../sysdeps/nptl/libc_start_call_main.h:58:16
#8 0x757b23829e3f in __libc_start_main csu/../csu/libc-start.c:392:3
#9 0x5584c61c0414 in _start (/cJSON/5+0x1f414) (BuildId: 675a8db95ab4b2105e92973333a1dd1eccdabf1b)
POC
https://github.com/Du4t/POC/blob/main/cJSON/poc-ApplyPatchesCaseSensitive-SEGV
Impact
Potentially causing DoS
- Lenguaje dominante
- C
- Estrellas
- 13k
- Forks
- 3.5k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de DaveGamble/cJSON
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
DaveGamble/cJSON#1094 · 1 reacción ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
DaveGamble/cJSON#1093 ·
-
Use-after-free in cJSONUtils_ApplyPatches when a patch removes the patch arrayPosiblemente ocupada @iliasabk la tomó hace 22 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
DaveGamble/cJSON#1082 ·
-
Use-after-free in cJSON_ReplaceItemInObject when the key is the item's own namePosiblemente ocupada @iliasabk la tomó hace 23 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
DaveGamble/cJSON#1081 ·
-
buffer_skip_whitespace accepts every byte below 0x21 as whitespacePosiblemente ocupada @AetherAI3 la tomó hace 34 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
DaveGamble/cJSON#1074 ·
Todos los issues de DaveGamble/cJSON
Issues similares
-
backlog
Dificultad 1/5 Menos de una hora Aptitud para principiantes 82/100
EchoTools/nevr-runtime#454 ·
Los mantenedores suelen responder en 1 día
-
initramfs: -type f (#18686) skips the libcurl.so.4 symlink, libcurl no longer copied into initramfsAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 2 días
-
common/json_parse: json_to_bitcoin_amount fails to detect overflow and accepts negative/empty inputsPosiblemente ocupada @bhuvan-somisetty la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
ElementsProject/lightning#9617 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 62/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
zephyrproject-rtos/zephyr#121795 ·
Los mantenedores suelen responder en 2 días