Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[BUG] Use-After-Free (8-byte pointer write) in cJSON_Utils.c: sort_list() breaks the child->prev invariant

Đang mở
#1,090 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
76/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
c
Lĩnh vực
security

Hướng nghiên cứu

Start with sort_list() in cJSON_Utils.c around line 484, then read the child->prev handling in cJSON.c around lines 1761, 2001, 2052, and 2284. Build and run the supplied poc_min.c with the documented AddressSanitizer command. Done means the reproduction no longer reports the use-after-free after sorting, removing an interior member, and adding a member.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

I found a UAF caused by sort_list() in cJSON_Utils.c.It rebuilds an object's doubly linked list with mergesort but never restores cJSON's invariant child->prev == tail. After a sort, head->prev is either NULL or a live interior node. If that interior node is later removed (freed) and a member is then added to the same object, add_item_to_array() runs suffix_object(child->prev, item) → prev->next = item , writing 8-byte write into freed heap memory.

Branch : master 6d9f2443ab071f86e5d9b43025a40929ec41c46c.

Root cause

sort_list() (cJSON_Utils.c:484), merge loop:

if (result == NULL)
{
    /* start merged list with the smaller element */
    result_tail = smaller;
    result = smaller;      /* smaller->prev keeps its pre-sort value */
}

Only ->next and the prev of subsequently appended elements are maintained. The split path explicitly sets second->prev = NULL (cJSON_Utils.c:~528), so the stale value on the merged head is either NULL or a node that is still in the list.
cJSON depends on child->prev == tail. Established by the parser: head->prev = current_item (cJSON.c:1761) and consumed by add_item_to_array(): suffix_object(child->prev, item) (cJSON.c:2052) → prev->next = item (cJSON.c:2001).But the detach path only repairs it when the tail is removed (cJSON.c:2284), so deleting an interior node leaves child->prev dangling.

Reproduction (attached: poc_min.c)

three public API calls

gcc -g -O1 -fsanitize=address -I. cJSON.c cJSON_Utils.c poc_min.c -o poc_min -lm
./poc_min
POC

poc_min.c

asan-log.txt

Ngôn ngữ chính
C
Star
13k
Fork
3.5k
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của DaveGamble/cJSON

Tất cả issue của DaveGamble/cJSON

Issue tương tự

Thêm issue về C

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.