[Security] Stack Overflow via Uncontrolled Recursion in cJSONUtils_MergePatch
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
Direzione di ricerca
Inizia con cJSONUtils_MergePatch e la logica di merge_tests in tests/old_utils_tests.c, quindi confronta la relativa gestione della ricorsione con il comportamento di CJSON_NESTING_LIMIT menzionato nell’issue. Compila con ENABLE_CJSON_UTILS e ENABLE_CJSON_TEST, riproduci il caso a 30,000 livelli e considera il lavoro completato quando la patch annidata non causa più un segmentation fault e la regressione è coperta dalla suite di test.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Clear and concise description of the bug:
A stack overflow vulnerability exists in the cJSON_Utils library due to uncontrolled recursion in the cJSONUtils_MergePatch function. When processing a JSON Merge Patch (RFC 7396) with deeply nested objects, the function recursively traverses the patch without any depth limit. This exhausts the system stack memory, leading to a segmentation fault and application crash (Denial of Service).
Steps to reproduce the bug :
To reproduce this with the existing test suite, modify tests/old_utils_tests.c to dynamically inject a deeply nested object:
1.Increase the size of the merges array and add a placeholder:
static const char *merges[16][3] = {
// ... existing tests ...
{"{}", "RECURSIVE_PLACEHOLDER", "{}"}
};
2.Modify the test loop in merge_tests to dynamically build a 30,000-layer object when the placeholder is encountered:
if (strcmp(merges[i][1], "RECURSIVE_PLACEHOLDER") == 0) {
int depth = 30000;
int d = 0;
patch = cJSON_CreateObject();
cJSON *current = patch;
for (d = 0; d < depth; d++) {
cJSON *next = cJSON_CreateObject();
cJSON_AddItemToObject(current, "a", next);
current = next;
}
}
3.Build and run the tests:
mkdir build
cd build
cmake .. -DENABLE_CJSON_UTILS=On -DENABLE_CJSON_TEST=On -DCMAKE_BUILD_TYPE=Debug
make
./tests/old_utils_tests .
Expected behavior:
The function should either successfully process the nested structure or, more appropriately, return an error when a pre-defined recursion depth limit is exceeded, similar to the CJSON_NESTING_LIMIT enforced in the core library.
Observed behavior:
The program crashes with a Segmentation fault. GDB backtrace shows thousands of recursive calls to merge_patch (frames reaching over #13000), eventually exhausting the default stack size.
Platform(s) (compiler version, operating system version, CPU) on which the bug was observed:
OS: Ubuntu Linux 20.04+
Compiler: GCC
cJSON release(s), commit(s), or branch(es) in which the bug was observed :
cJSON(main branch)
- Lingua principale
- C
- Stelle
- 13k
- Fork
- 3.5k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di DaveGamble/cJSON
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
DaveGamble/cJSON#1094 · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
DaveGamble/cJSON#1093 ·
-
Use-after-free in cJSONUtils_ApplyPatches when a patch removes the patch arrayForse già presa @iliasabk l’ha presa 21 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
DaveGamble/cJSON#1082 ·
-
Use-after-free in cJSON_ReplaceItemInObject when the key is the item's own nameForse già presa @iliasabk l’ha presa 22 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
DaveGamble/cJSON#1081 ·
-
buffer_skip_whitespace accepts every byte below 0x21 as whitespaceForse già presa @AetherAI3 l’ha presa 33 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
DaveGamble/cJSON#1074 ·
Tutte le issue di DaveGamble/cJSON
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
severity: low
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
luainkernel/lunatik#1853 ·
I maintainer di solito rispondono entro 1 giorno
-
encoding.binary: bounds check guard is compiled away, so decode functions read past the sliceAperta
Difficoltà 2/5 Mezza giornata Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
resetes12/pokeemerald#204 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 6 giorni