Unsound usages of unsafe implementation about c_void
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 30/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- rust
- 领域
- networking
调研方向
从 src/netmap_user.rs:16 和 _NETMAP_OFFSET 函数开始,然后检查 Rust 关于 raw-pointer offset、对齐和边界的未定义行为要求。根据该函数的调用方验证 static-analyzer 报告,并确定所报告的转换是否会产生其声称的内存安全问题。完成的标准是该发现已有明确的解决结论和适当的验证。
由索引模型根据 Issue 内容生成。
描述
Hi, I am scanning this crate in the latest version using my own static analyzer tool.
Unsafe pointer conversion is found at: src/netmap_user.rs:16
pub unsafe fn _NETMAP_OFFSET<T, U>(ptr: *mut U, offset: isize) -> *mut T {
((ptr as *mut c_char).offset(offset) as *mut c_void) as *mut T
}
This unsound implementation would create memory issues such as overflow, underflow, or misalignment, since the type is converted to c_void (1 byte, 8 bits). The attacker can manipulate the argument offset associated with the c_void pointer with a large value, as well as T and U, which can lead to a buffer overflow bug.
This would cause undefined behaviors in Rust. Adversaries can manipulate the associated arguments to cause memory safety bugs. I am reporting this issue for your attention.
- 主要语言
- Rust
- 星标
- 28
- 派生
- 11
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
libpnet/netmap_sys 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 65/100
libpnet/netmap_sys#21 · 2 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 48/100
libpnet/netmap_sys#22 · 1 条评论 ·
查看 libpnet/netmap_sys 的全部 Issue
相似的 Issue
-
bug CLI custom-model
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
rust-bitcoin/rust-bitcoin#6930 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
fulcrumgenomics/ferro-hgvs#2251 ·
-
A-allocators A-docs C-enhancement T-libs
难度 2/5 1-3 小时 新手友好度 75/100