envoyproxy/envoy

[kafka_broker] potential out of memory with untrusted buffer when onData()

Open

#12,687 建立於 2020年8月17日

在 GitHub 查看
 (2 留言) (0 反應) (0 負責人)C++ (5,373 fork)batch import
area/kafkahelp wanted

倉庫指標

Star
 (27,997 star)
PR 合併指標
 (平均合併 8天) (30 天內合併 378 個 PR)

描述

Since documentation of kafka_broker shows it is still an alpha version, and only accept trusted data, I think this is not a security issue, so I post it here.

The ArrayDeserializer reads an integer from the buffer and uses it as the size of a new vector(variable name: required_): https://github.com/envoyproxy/envoy/blob/master/source/extensions/filters/network/kafka/serialization.h#L466

If the input is invalid or from untrusted downstream, it's possible that the length is very large(9999999) but actually the buffer size is only 20.

We may consider adding a constraint on the vector length(for example, not more than buffer.size()?) to avoid this bug.

The issue and test case can be found here: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24862&sort=-opened&can=1&q=proj%3Aenvoy%20status%3DNew

貢獻者指南