[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized Input
Los mantenedores suelen responder en 1 día
@Acen28 ya está trabajando en esto.
Desde el 26/9/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
RT-Thread Version
v5.3.0/git-hash: cda0a63
Affected area
FinSH
Hardware/BSP vendor
STM32
Architecture
ARM / AArch64
Board and hardware details
bsp/stm32/stm32f407-atk-explorer
Develop Toolchain
GCC
Describe the bug
Description
A critical Heap Out-of-Bounds (OOB) Write vulnerability (CWE-122) exists within the RT-Thread FinSH component, specifically in the path auto-completion logic (msh_auto_complete_path or related directory parsing functions).
When a user interacts with the msh shell (e.g., via a serial terminal or a remote network console) and attempts to trigger path auto-completion (typically using the <Tab> key) on an excessively long or deeply nested directory string, the underlying string manipulation routine fails to enforce strict boundary checks.
The function allocates a fixed-size buffer on the heap (often bounded by macros like RT_PATH_MAX or a hardcoded 256 bytes, e.g., full_path). During the concatenation of the current working directory and the user-supplied input, a while loop or strcpy/memcpy equivalent copies the oversized input string past the allocated bounds of the heap buffer.
This silent memory corruption overwrites adjacent heap metadata. The system does not crash immediately upon the OOB write. However, during the next memory allocation or deallocation cycle, the corrupted heap metadata is dereferenced, leading to an immediate HardFault or offering an attacker the potential for Heap-based Arbitrary Code Execution.
Prerequisites to Reproduce
- The FinSH/msh component is enabled and accessible to the user/attacker.
- The
RT_USING_DFS(Device Virtual File System) andRT_USING_DFS_DEVFSare enabled, allowing directory traversal and path completion.
Steps to Reproduce
- Boot the RT-Thread system and connect to the FinSH interactive shell (via UART or Telnet).
- Input an excessively long string intended as a directory path. For example, input
cd /followed by a payload of over 256 'A' characters:
msh > cd /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA... - Trigger the auto-complete function (usually by sending the
\t(Tab) character via the input stream). - The
msh_auto_complete_pathfunction attempts to parse and concatenate the path. The oversized string silently overflows thefull_pathheap buffer. - Execute any subsequent command that requires dynamic memory allocation (e.g.,
lsor running a network task). - The system throws a HardFault (or MemManage fault) due to corrupted heap metadata during
rt_mallocorrt_free.
Other additional context
No response
- Lenguaje dominante
- C
- Estrellas
- 12.3k
- Forks
- 5.5k
- Merge medio
- 4 d 12 h
- PR fusionados (30 d)
- 32
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de RT-Thread/rt-thread
-
bug Component component: net
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
RT-Thread/rt-thread#11852 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[bsp][stm32][bluepill] README「快速上手」缺少重新生成 MDK 工程这一步,按文档操作无法编译通过Posiblemente ocupada @moment-NEW la tomó hace 2 días. Abiertoin progress
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
RT-Thread/rt-thread#11818 · 4 comentarios · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
BSP BSP: Loongson bug RT-Smart
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RT-Thread/rt-thread#11717 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Arch: RISC-V BSP BSP: HPMicro bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RT-Thread/rt-thread#11687 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
RT-Thread/rt-thread#11472 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de RT-Thread/rt-thread
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
siderolabs/pkgs#1710 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
qmk/qmk_firmware#26498 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
MixinNetwork/flutter-plugins#512 ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
betaflight/betaflight#15801 ·
Los mantenedores suelen responder en 2 días