IIS: ReadFileChunk allocates only 1 byte but reads m_dwPageSize (latent overflow)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
iis/mymodule.cpp を開いて ReadFileChunk を調査し、1274 行目の m_dwPageSize の設定も確認します。VirtualAlloc の要求を更新して、そのサイズが ReadFile の長さと一致するようにし、既存の VirtualFree のクリーンアップが変更されていないことを確認してから、IIS モジュールのビルドまたは利用可能であれば関連するテストを確認します。
索引モデルが issue の本文から書いたものです。
説明
Summary
In iis/mymodule.cpp, ReadFileChunk allocates its I/O scratch buffer with VirtualAlloc(NULL, 1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE) but then reads m_dwPageSize bytes into it via ReadFile.
pIoBuffer = (BYTE *)VirtualAlloc(NULL, 1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
// ...
if (!ReadFile(..., pIoBuffer, m_dwPageSize, ...))
This only "works" by accident: VirtualAlloc's allocation size is rounded up to a full page (the system page size, obtained as sysInfo.dwPageSize → m_dwPageSize, mymodule.cpp:1274), and the returned address is page-aligned. So requesting 1 byte effectively commits one page, which happens to be exactly m_dwPageSize bytes — and ReadFile writes exactly that many.
Why it is a latent bug
- The code relies on an implicit, undocumented assumption that
m_dwPageSizeequals the system page size. If that ever differs (large-page configuration, or the value being mis-tuned larger),ReadFilewrites past the committed region → access violation. VirtualAlloc(..., 1, ...)is misleading and fragile; the real buffer size is invisible at the call site.
Suggested fix
Allocate the real size explicitly:
pIoBuffer = (BYTE *)VirtualAlloc(NULL, m_dwPageSize, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
The page-aligned address still satisfies the file I/O alignment requirements already used in the function, and the committed size now matches the ReadFile length. The existing VirtualFree(pIoBuffer, 0, MEM_RELEASE) cleanup is unaffected (it releases the whole region regardless of size).
- 主要言語
- C++
- スター
- 9.8k
- フォーク
- 1.8k
- 平均マージ
- 2時間 46分
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
owasp-modsecurity/ModSecurity のほかの issue
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
owasp-modsecurity/ModSecurity#3621 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
owasp-modsecurity/ModSecurity#3619 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
owasp-modsecurity/ModSecurity#3612 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
3.x
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
owasp-modsecurity/ModSecurity#3580 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 25/100
owasp-modsecurity/ModSecurity#3630 ·
メンテナーはふだん 1 日以内に返信
owasp-modsecurity/ModSecurity の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
grumpycoders/pcsx-redux#2171 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
bytedance/trae-agent#524 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 84/100
AcademySoftwareFoundation/openexr#2683 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
microsoft/onnxruntime#32881 ·
メンテナーはふだん 1 日以内に返信