Repository navigation
Modules/cjkcodecs/_codecs_iso2022.c - read out of bounds #101180
Copy link
Copy link
Closed
Labels
topic-unicodetype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-securityA security issueA security issue
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Jan 20, 2023 - added a commit that references this issue
on Feb 8, 2023 - changed the title
[-]Modules/cjkcodecs/_codecs_iso2022.c:808 - Read of Bounds[/-][+]Modules/cjkcodecs/_codecs_iso2022.c - read out of bounds[/+]on Feb 8, 2023 I turned your report into a PR, It should show up in the CI address sanitizer run there. (confirmed locally)
Hi everyone!
Found a new read-of-bounds vulnerability:==17275==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fc39f9daf34 at pc 0x7fc3a10f9c6d bp 0x7ffe1ba83600 sp 0x7ffe1ba835f8 READ of size 4 at 0x7fc39f9daf34 thread T0 #0 0x7fc3a10f9c6c in jisx0213_encoder /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:808 #1 0x7fc3a10f9c6c in jisx0213_2004_1_encoder_paironly /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:894 #2 0x7fc3a10f3bcf in iso2022_encode /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:196 #3 0x7fc3a10e4b45 in multibytecodec_encode /home/kali/python3.10.12/Modules/cjkcodecs/multibytecodec.c:526 #4 0x7fc3a10e6c1d in _multibytecodec_MultibyteCodec_encode_impl /home/kali/python3.10.12/Modules/cjkcodecs/multibytecodec.c:623 #5 0x7fc3a10e6c1d in _multibytecodec_MultibyteCodec_encode /home/kali/python3.10.12/Modules/cjkcodecs/clinic/multibytecodec.c.h:62 #6 0x55cc82fed2bf in cfunction_vectorcall_FASTCALL_KEYWORDS Objects/methodobject.c:446 #7 0x55cc82b6c970 in PyVectorcall_Call Objects/call.c:255 #8 0x55cc82d3354a in _PyCodec_EncodeInternal Python/codecs.c:420 #9 0x55cc82ec1a47 in _codecs_encode_impl Modules/_codecsmodule.c:131 #10 0x55cc82ec1a47 in _codecs_encode Modules/clinic/_codecsmodule.c.h:137 #11 0x55cc82fed2bf in cfunction_vectorcall_FASTCALL_KEYWORDS Objects/methodobject.c:446 #12 0x55cc82b3632c in _PyObject_VectorcallTstate Include/cpython/abstract.h:114 #13 0x55cc82b3632c in PyObject_Vectorcall Include/cpython/abstract.h:123 #14 0x55cc82b3632c in call_function Python/ceval.c:5893 #15 0x55cc82b3632c in _PyEval_EvalFrameDefault Python/ceval.c:4231 #16 0x55cc82d2dbb1 in _PyEval_EvalFrame Include/internal/pycore_ceval.h:46 #17 0x55cc82d2dbb1 in _PyEval_Vector Python/ceval.c:5067 #18 0x55cc82d2dbb1 in PyEval_EvalCode Python/ceval.c:1134 #19 0x55cc82defe6b in run_eval_code_obj Python/pythonrun.c:1291 #20 0x55cc82defe6b in run_mod Python/pythonrun.c:1312 #21 0x55cc82df28df in pyrun_file Python/pythonrun.c:1208 #22 0x55cc82df28df in _PyRun_SimpleFileObject Python/pythonrun.c:456 #23 0x55cc82df3464 in _PyRun_AnyFileObject Python/pythonrun.c:90 #24 0x55cc82b44f9e in pymain_run_file_obj Modules/main.c:353 #25 0x55cc82b44f9e in pymain_run_file Modules/main.c:372 #26 0x55cc82b44f9e in pymain_run_python Modules/main.c:587 #27 0x55cc82b46743 in Py_RunMain Modules/main.c:666 #28 0x55cc82b46743 in pymain_main Modules/main.c:696 #29 0x55cc82b46743 in Py_BytesMain Modules/main.c:720 #30 0x7fc3a1846189 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 #31 0x7fc3a1846244 in __libc_start_main_impl ../csu/libc-start.c:381 #32 0x55cc82b42b60 in _start (/home/kali/python3.10.12/python+0x176b60) (BuildId: 6292689f0cb3a264af4e67751a64a14c9a1caac4) Address 0x7fc39f9daf34 is located in stack of thread T0 at offset 52 in frame #0 0x7fc3a10f363f in iso2022_encode /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:157 This frame has 2 object(s): [48, 52) 'c' (line 161) <== Memory access at offset 52 overflows this variable [64, 72) 'length' (line 184) HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions *are* supported) SUMMARY: AddressSanitizer: stack-buffer-overflow /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:808 in jisx0213_encoder Shadow bytes around the buggy address: 0x7fc39f9dac80: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 0x7fc39f9dad00: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 0x7fc39f9dad80: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 00 00 00 00 0x7fc39f9dae00: f1 f1 f1 f1 f8 f2 f2 f2 00 f2 f2 f2 00 00 f3 f3 0x7fc39f9dae80: f1 f1 f1 f1 00 00 00 00 00 00 00 f3 f3 f3 f3 f3 =>0x7fc39f9daf00: f1 f1 f1 f1 f1 f1[04]f2 00 f3 f3 f3 00 00 00 00 0x7fc39f9daf80: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 00 00 00 00 0x7fc39f9db000: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 0x7fc39f9db080: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 0x7fc39f9db100: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 0x7fc39f9db180: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 00 00 00 00 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==17275==ABORTING8 remaining items
- added a commit that references this issue
on Nov 6, 2023 - added 6 commits that reference this issue
on Nov 6, 2023
Metadata
Metadata
Labels
topic-unicodetype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-securityA security issueA security issue
Bug report
Your environment
Steps to reproduce
Prerequisites
crashfile.txt
test.py
Linked PRs