Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

IIS: ReadFileChunk allocates only 1 byte but reads m_dwPageSize (latent overflow)

オープン 初心者向け
#3,623 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
1/5
見積もり時間
1時間未満
初心者へのやさしさ
90/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
cpp
領域
security

調査の方向性

iis/mymodule.cpp を開いて ReadFileChunk を調査し、1274 行目の m_dwPageSize の設定も確認します。VirtualAlloc の要求を更新して、そのサイズが ReadFile の長さと一致するようにし、既存の VirtualFree のクリーンアップが変更されていないことを確認してから、IIS モジュールのビルドまたは利用可能であれば関連するテストを確認します。

索引モデルが issue の本文から書いたものです。

説明

2.x Platform - IIS

Summary

In iis/mymodule.cpp, ReadFileChunk allocates its I/O scratch buffer with VirtualAlloc(NULL, 1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE) but then reads m_dwPageSize bytes into it via ReadFile.

pIoBuffer = (BYTE *)VirtualAlloc(NULL, 1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
// ...
if (!ReadFile(..., pIoBuffer, m_dwPageSize, ...))

This only "works" by accident: VirtualAlloc's allocation size is rounded up to a full page (the system page size, obtained as sysInfo.dwPageSize → m_dwPageSize, mymodule.cpp:1274), and the returned address is page-aligned. So requesting 1 byte effectively commits one page, which happens to be exactly m_dwPageSize bytes — and ReadFile writes exactly that many.

Why it is a latent bug

  • The code relies on an implicit, undocumented assumption that m_dwPageSize equals the system page size. If that ever differs (large-page configuration, or the value being mis-tuned larger), ReadFile writes past the committed region → access violation.
  • VirtualAlloc(..., 1, ...) is misleading and fragile; the real buffer size is invisible at the call site.

Suggested fix

Allocate the real size explicitly:

pIoBuffer = (BYTE *)VirtualAlloc(NULL, m_dwPageSize, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);

The page-aligned address still satisfies the file I/O alignment requirements already used in the function, and the committed size now matches the ReadFile length. The existing VirtualFree(pIoBuffer, 0, MEM_RELEASE) cleanup is unaffected (it releases the whole region regardless of size).

主要言語
C++
スター
9.8k
フォーク
1.8k
平均マージ
2時間 46分
マージ済み PR(30日)
1

環境構築

  • Dockerfile・Docker Compose ファイルなし
  • プルリクエストのテンプレートあり
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

owasp-modsecurity/ModSecurity のほかの issue

owasp-modsecurity/ModSecurity の issue をすべて見る

似ている issue

C++ の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。