[BUG] Use-After-Free (8-byte pointer write) in cJSON_Utils.c: sort_list() breaks the child->prev invariant
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 76/100
Hướng nghiên cứu
Start with sort_list() in cJSON_Utils.c around line 484, then read the child->prev handling in cJSON.c around lines 1761, 2001, 2052, and 2284. Build and run the supplied poc_min.c with the documented AddressSanitizer command. Done means the reproduction no longer reports the use-after-free after sorting, removing an interior member, and adding a member.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
I found a UAF caused by sort_list() in cJSON_Utils.c.It rebuilds an object's doubly linked list with mergesort but never restores cJSON's invariant child->prev == tail. After a sort, head->prev is either NULL or a live interior node. If that interior node is later removed (freed) and a member is then added to the same object, add_item_to_array() runs suffix_object(child->prev, item) → prev->next = item , writing 8-byte write into freed heap memory.
Branch : master 6d9f2443ab071f86e5d9b43025a40929ec41c46c.
Root cause
sort_list() (cJSON_Utils.c:484), merge loop:
if (result == NULL)
{
/* start merged list with the smaller element */
result_tail = smaller;
result = smaller; /* smaller->prev keeps its pre-sort value */
}
Only ->next and the prev of subsequently appended elements are maintained. The split path explicitly sets second->prev = NULL (cJSON_Utils.c:~528), so the stale value on the merged head is either NULL or a node that is still in the list.
cJSON depends on child->prev == tail. Established by the parser: head->prev = current_item (cJSON.c:1761) and consumed by add_item_to_array(): suffix_object(child->prev, item) (cJSON.c:2052) → prev->next = item (cJSON.c:2001).But the detach path only repairs it when the tail is removed (cJSON.c:2284), so deleting an interior node leaves child->prev dangling.
Reproduction (attached: poc_min.c)
three public API calls
gcc -g -O1 -fsanitize=address -I. cJSON.c cJSON_Utils.c poc_min.c -o poc_min -lm
./poc_min
POC
- Ngôn ngữ chính
- C
- Star
- 13k
- Fork
- 3.5k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của DaveGamble/cJSON
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
DaveGamble/cJSON#1094 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
DaveGamble/cJSON#1093 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
DaveGamble/cJSON#1082 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
DaveGamble/cJSON#1081 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
DaveGamble/cJSON#1074 ·
Tất cả issue của DaveGamble/cJSON
Issue tương tự
-
Status: Opened
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
darktable-org/darktable#22455 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:ci kind:gate-defect
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
InauguralSystems/EigenScript#1448 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
BasedHardware/omi#20084 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
raspberrypi/pico-sdk#3225 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày