The check_overflow() function can work incorrectly in some cases
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 25/100
Línea de trabajo
Read check_overflow() in common.c at the linked location and trace how it checks the product of its three unsigned int arguments. The issue gives two argument combinations that can expose the incorrect check; use them to assess whether the overflow is detected. Done means the check handles these cases without overflowing its intermediate calculation.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
The check_overflow() function has been implemented to check an overflow of the product of three numbers.
Here is the declaration:
void check_overflow(unsigned int val1, unsigned int val2, unsigned int val3)
Unfortunately, the implementation you can see here isn't tolerant against an arithmetic overflow at least on 64bit systems. Please, pay attention that sizeof(unsigned long long) == 8, so it can hold values no more than 2^64-1, but each of val1, val2, and val3 can hold values up to 2^32-1, so the product of (2^32-1) * (2^32-1) * (2^32-1) overflows the 64-bit variable.
However, not every overflow leads to a failing check, most cases still detect an overflow even the product has been truncated, but there are combinations of arguments when things go wrong, for example:
check_overflow(UINT_MAX, UINT_MAX, 2147483648),check_overflow(UINT_MAX-100, UINT_MAX-5, 2849931574)
and so on.
It seems the CVE-2022-39377 is still exploitable in some conditions.
- Lenguaje dominante
- C
- Estrellas
- 3.4k
- Forks
- 490
- Merge medio
- 3 d 14 h
- PR fusionados (30 d)
- 5
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de sysstat/sysstat
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 40/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
-
sar: duplicate interrupts when using SUM while reading interrupts in 390x arch (from `/proc/interrupts`)Quizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
Todos los issues de sysstat/sysstat
Issues similares
-
Linux notifications: the default action's ' ' label shows as a blank button in xfce4-notifydAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
kovidgoyal/kitty#10625 ·
Los mantenedores suelen responder en 1 día
-
Feature Status: Needs Triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 73/100
Los mantenedores suelen responder en 1 día
-
docs
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
本機相簿無法上傳webm檔案Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
xiaojieonly/Ehviewer_CN_SXJ#2893 ·