IIS: ReadFileChunk allocates only 1 byte but reads m_dwPageSize (latent overflow)
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 1/5
- Tiempo estimado
- Menos de una hora
- Aptitud para principiantes
- 90/100
Línea de trabajo
Abre iis/mymodule.cpp e inspecciona ReadFileChunk, incluida la configuración de m_dwPageSize en la línea 1274. Actualiza la solicitud de VirtualAlloc para que su tamaño coincida con la longitud de ReadFile; después, verifica que la limpieza existente de VirtualFree permanezca sin cambios y revisa la compilación del módulo de IIS o las pruebas relevantes, si están disponibles.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
In iis/mymodule.cpp, ReadFileChunk allocates its I/O scratch buffer with VirtualAlloc(NULL, 1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE) but then reads m_dwPageSize bytes into it via ReadFile.
pIoBuffer = (BYTE *)VirtualAlloc(NULL, 1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
// ...
if (!ReadFile(..., pIoBuffer, m_dwPageSize, ...))
This only "works" by accident: VirtualAlloc's allocation size is rounded up to a full page (the system page size, obtained as sysInfo.dwPageSize → m_dwPageSize, mymodule.cpp:1274), and the returned address is page-aligned. So requesting 1 byte effectively commits one page, which happens to be exactly m_dwPageSize bytes — and ReadFile writes exactly that many.
Why it is a latent bug
- The code relies on an implicit, undocumented assumption that
m_dwPageSizeequals the system page size. If that ever differs (large-page configuration, or the value being mis-tuned larger),ReadFilewrites past the committed region → access violation. VirtualAlloc(..., 1, ...)is misleading and fragile; the real buffer size is invisible at the call site.
Suggested fix
Allocate the real size explicitly:
pIoBuffer = (BYTE *)VirtualAlloc(NULL, m_dwPageSize, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
The page-aligned address still satisfies the file I/O alignment requirements already used in the function, and the committed size now matches the ReadFile length. The existing VirtualFree(pIoBuffer, 0, MEM_RELEASE) cleanup is unaffected (it releases the whole region regardless of size).
- Lenguaje dominante
- C++
- Estrellas
- 9.8k
- Forks
- 1.8k
- Merge medio
- 2 h 46 min
- PR fusionados (30 d)
- 1
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de owasp-modsecurity/ModSecurity
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
owasp-modsecurity/ModSecurity#3621 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
owasp-modsecurity/ModSecurity#3619 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
owasp-modsecurity/ModSecurity#3612 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
3.x
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
owasp-modsecurity/ModSecurity#3580 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
2.x Platform - IIS
Dificultad 2/5 1-3 horas Aptitud para principiantes 25/100
owasp-modsecurity/ModSecurity#3630 ·
Los mantenedores suelen responder en 1 día
Todos los issues de owasp-modsecurity/ModSecurity
Issues similares
-
Broken links in the docsAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
microsoft/onnxruntime#33018 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
DataLakeFileSystemClient::ListPaths() throws JSON exception due to accessing undefined fieldsAbiertocustomer-reported needs-triage question
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Azure/azure-sdk-for-cpp#7435 ·
Los mantenedores suelen responder en 1 día
-
ChromieCraft Generic Confirmed World Event
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
azerothcore/azerothcore-wotlk#27882 ·
Los mantenedores suelen responder en 1 día
-
MacOS build failureAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
aristocratos/btop#1874 ·
Los mantenedores suelen responder en 1 día