Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized Input

未关闭
#11,839 3 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

维护者通常 1 天内回复

@Acen28 已经在做这个了。

开始于 2026年9月26日。

评估

这个 Issue 还没有评估数据。

描述

Arch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread Version

v5.3.0/git-hash: cda0a63

Affected area

FinSH

Hardware/BSP vendor

STM32

Architecture

ARM / AArch64

Board and hardware details

bsp/stm32/stm32f407-atk-explorer

Develop Toolchain

GCC

Describe the bug

Description
A critical Heap Out-of-Bounds (OOB) Write vulnerability (CWE-122) exists within the RT-Thread FinSH component, specifically in the path auto-completion logic (msh_auto_complete_path or related directory parsing functions).

When a user interacts with the msh shell (e.g., via a serial terminal or a remote network console) and attempts to trigger path auto-completion (typically using the <Tab> key) on an excessively long or deeply nested directory string, the underlying string manipulation routine fails to enforce strict boundary checks.

The function allocates a fixed-size buffer on the heap (often bounded by macros like RT_PATH_MAX or a hardcoded 256 bytes, e.g., full_path). During the concatenation of the current working directory and the user-supplied input, a while loop or strcpy/memcpy equivalent copies the oversized input string past the allocated bounds of the heap buffer.

This silent memory corruption overwrites adjacent heap metadata. The system does not crash immediately upon the OOB write. However, during the next memory allocation or deallocation cycle, the corrupted heap metadata is dereferenced, leading to an immediate HardFault or offering an attacker the potential for Heap-based Arbitrary Code Execution.

Prerequisites to Reproduce

  1. The FinSH/msh component is enabled and accessible to the user/attacker.
  2. The RT_USING_DFS (Device Virtual File System) and RT_USING_DFS_DEVFS are enabled, allowing directory traversal and path completion.

Steps to Reproduce

  1. Boot the RT-Thread system and connect to the FinSH interactive shell (via UART or Telnet).
  2. Input an excessively long string intended as a directory path. For example, input cd / followed by a payload of over 256 'A' characters:
    msh > cd /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...
  3. Trigger the auto-complete function (usually by sending the \t (Tab) character via the input stream).
  4. The msh_auto_complete_path function attempts to parse and concatenate the path. The oversized string silently overflows the full_path heap buffer.
  5. Execute any subsequent command that requires dynamic memory allocation (e.g., ls or running a network task).
  6. The system throws a HardFault (or MemManage fault) due to corrupted heap metadata during rt_malloc or rt_free.
Other additional context

No response

主要语言
C
星标
12.3k
派生
5.5k
平均合并
4 天 12 小时
30 天内合并 PR
32

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

RT-Thread/rt-thread 的其他 Issue

查看 RT-Thread/rt-thread 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。