Visitar URL original
Modules/cjkcodecs/_codecs_iso2022.c - read out of bounds · Issue #101180 · python/cpython · GitHub
Skip to content

Modules/cjkcodecs/_codecs_iso2022.c - read out of bounds #101180

Description

@stasos24

Bug report

==2729==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffef35c8f14 at pc 0x7f3e0254c47c bp 0x7ffef35c8e50 sp 0x7ffef35c8e48
READ of size 4 at 0x7ffef35c8f14 thread T0
    #0 0x7f3e0254c47b in jisx0213_encoder Modules/cjkcodecs/_codecs_iso2022.c:808
    #1 0x7f3e0254c47b in jisx0213_2004_1_encoder_paironly Modules/cjkcodecs/_codecs_iso2022.c:894
    #2 0x7f3e025469a9 in iso2022_encode Modules/cjkcodecs/_codecs_iso2022.c:196
    #3 0x7f3e02536457 in multibytecodec_encode Modules/cjkcodecs/multibytecodec.c:523
    #4 0x7f3e0253829e in _multibytecodec_MultibyteCodec_encode_impl Modules/cjkcodecs/multibytecodec.c:620
    #5 0x7f3e0253829e in _multibytecodec_MultibyteCodec_encode Modules/cjkcodecs/clinic/multibytecodec.c.h:91
    #6 0x55e4cc690361 in cfunction_vectorcall_FASTCALL_KEYWORDS Objects/methodobject.c:438
    #7 0x55e4cc5b029e in PyObject_Call (/home/kali/Downloads/cpython/python+0x3e629e)
    #8 0x55e4cc841026 in _PyCodec_EncodeInternal Python/codecs.c:419
    #9 0x55e4cc9cb18f in _codecs_encode_impl Modules/_codecsmodule.c:132
    #10 0x55e4cc9cb18f in _codecs_encode Modules/clinic/_codecsmodule.c.h:166
    #11 0x55e4cc690361 in cfunction_vectorcall_FASTCALL_KEYWORDS Objects/methodobject.c:438
    #12 0x55e4cc5af6bf in _PyObject_VectorcallTstate Include/internal/pycore_call.h:92
    #13 0x55e4cc5af6bf in PyObject_Vectorcall Objects/call.c:301
    #14 0x55e4cc4753f6 in _PyEval_EvalFrameDefault Python/generated_cases.c.h:2982
    #15 0x55e4cc83c811 in _PyEval_EvalFrame Include/internal/pycore_ceval.h:88
    #16 0x55e4cc83c811 in _PyEval_Vector Python/ceval.c:1716
    #17 0x55e4cc83c811 in PyEval_EvalCode Python/ceval.c:578
    #18 0x55e4cc91aebd in run_eval_code_obj Python/pythonrun.c:1702
    #19 0x55e4cc91aebd in run_mod Python/pythonrun.c:1723
    #20 0x55e4cc91e6ca in pyrun_file Python/pythonrun.c:1617
    #21 0x55e4cc91e6ca in _PyRun_SimpleFileObject Python/pythonrun.c:439
    #22 0x55e4cc91f17a in _PyRun_AnyFileObject Python/pythonrun.c:78
    #23 0x55e4cc976719 in pymain_run_file_obj Modules/main.c:360
    #24 0x55e4cc976719 in pymain_run_file Modules/main.c:379
    #25 0x55e4cc976719 in pymain_run_python Modules/main.c:610
    #26 0x55e4cc977ebc in Py_RunMain Modules/main.c:689
    #27 0x55e4cc977ebc in pymain_main Modules/main.c:719
    #28 0x55e4cc977ebc in Py_BytesMain Modules/main.c:743
    #29 0x7f3e052d6209 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
    #30 0x7f3e052d62bb in __libc_start_main_impl ../csu/libc-start.c:389
    #31 0x55e4cc49c3f0 in _start (/home/kali/Downloads/cpython/python+0x2d23f0)

Address 0x7ffef35c8f14 is located in stack of thread T0 at offset 52 in frame
    #0 0x7f3e0254644f in iso2022_encode Modules/cjkcodecs/_codecs_iso2022.c:157

  This frame has 2 object(s):
    [48, 52) 'c' (line 161) <== Memory access at offset 52 overflows this variable
    [64, 72) 'length' (line 184)
HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork
      (longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow Modules/cjkcodecs/_codecs_iso2022.c:808 in jisx0213_encoder
Shadow bytes around the buggy address:
  0x10005e6b1190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x10005e6b11a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x10005e6b11b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x10005e6b11c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x10005e6b11d0: 00 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1
=>0x10005e6b11e0: f1 f1[04]f2 00 f3 f3 f3 00 00 00 00 00 00 00 00
  0x10005e6b11f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x10005e6b1200: 00 00 00 00 f1 f1 f1 f1 00 00 00 00 00 00 00 f3
  0x10005e6b1210: f3 f3 f3 f3 00 00 00 00 00 00 00 00 00 00 00 00
  0x10005e6b1220: 00 00 00 00 f1 f1 f1 f1 f8 f2 f2 f2 00 f2 f2 f2
  0x10005e6b1230: 00 00 f3 f3 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
  Shadow gap:              cc
==2729==ABORTING

Your environment

  • CPython versions tested on: 3.12, 3.11, 3.10
  • Operating system and architecture: x86_x64 NAME="Kali GNU/Linux" "2022.3" (Reproduced also on other debian OS)

Steps to reproduce

  • CFLAGS="-fsanitize=address" CXXFLAGS="-fsanitize=address" LDFLAGS="-fsanitize=address" ./configure
  • make
  • copy test.py and crashfile to /cpython directory
  • run ./python test.py

Prerequisites

crashfile.txt
test.py

import codecs
f=open('crashfile.txt', 'r')
text=f.read()
print(text)
codecs.encode(text, encoding='iso2022_jp_2004', errors='ignore')

Linked PRs

Activity

  1. self-assigned this
    on Feb 8, 2023
  2. added a commit that references this issue on Feb 8, 2023
  3. changed the title [-]Modules/cjkcodecs/_codecs_iso2022.c:808 - Read of Bounds[/-] [+]Modules/cjkcodecs/_codecs_iso2022.c - read out of bounds[/+] on Feb 8, 2023
  4. gpshead commented on Feb 8, 2023

    @gpshead
    Member

    I turned your report into a PR, It should show up in the CI address sanitizer run there. (confirmed locally)

  5. removed their assignment
    on Feb 9, 2023
  6. gpshead commented on Feb 9, 2023

    @gpshead
    Member

    @hyeshik and @vstinner - thoughts?

  7. self-assigned this
    on Feb 9, 2023
  8. stasos24 commented on Oct 24, 2023

    @stasos24
    Author

    Hi everyone!
    Found a new read-of-bounds vulnerability:

    ==17275==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fc39f9daf34 at pc 0x7fc3a10f9c6d bp 0x7ffe1ba83600 sp 0x7ffe1ba835f8
    READ of size 4 at 0x7fc39f9daf34 thread T0                                                                                                                                                                                                 
        #0 0x7fc3a10f9c6c in jisx0213_encoder /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:808
        #1 0x7fc3a10f9c6c in jisx0213_2004_1_encoder_paironly /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:894
        #2 0x7fc3a10f3bcf in iso2022_encode /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:196
        #3 0x7fc3a10e4b45 in multibytecodec_encode /home/kali/python3.10.12/Modules/cjkcodecs/multibytecodec.c:526
        #4 0x7fc3a10e6c1d in _multibytecodec_MultibyteCodec_encode_impl /home/kali/python3.10.12/Modules/cjkcodecs/multibytecodec.c:623
        #5 0x7fc3a10e6c1d in _multibytecodec_MultibyteCodec_encode /home/kali/python3.10.12/Modules/cjkcodecs/clinic/multibytecodec.c.h:62
        #6 0x55cc82fed2bf in cfunction_vectorcall_FASTCALL_KEYWORDS Objects/methodobject.c:446
        #7 0x55cc82b6c970 in PyVectorcall_Call Objects/call.c:255
        #8 0x55cc82d3354a in _PyCodec_EncodeInternal Python/codecs.c:420
        #9 0x55cc82ec1a47 in _codecs_encode_impl Modules/_codecsmodule.c:131
        #10 0x55cc82ec1a47 in _codecs_encode Modules/clinic/_codecsmodule.c.h:137
        #11 0x55cc82fed2bf in cfunction_vectorcall_FASTCALL_KEYWORDS Objects/methodobject.c:446
        #12 0x55cc82b3632c in _PyObject_VectorcallTstate Include/cpython/abstract.h:114
        #13 0x55cc82b3632c in PyObject_Vectorcall Include/cpython/abstract.h:123
        #14 0x55cc82b3632c in call_function Python/ceval.c:5893
        #15 0x55cc82b3632c in _PyEval_EvalFrameDefault Python/ceval.c:4231
        #16 0x55cc82d2dbb1 in _PyEval_EvalFrame Include/internal/pycore_ceval.h:46
        #17 0x55cc82d2dbb1 in _PyEval_Vector Python/ceval.c:5067
        #18 0x55cc82d2dbb1 in PyEval_EvalCode Python/ceval.c:1134
        #19 0x55cc82defe6b in run_eval_code_obj Python/pythonrun.c:1291
        #20 0x55cc82defe6b in run_mod Python/pythonrun.c:1312
        #21 0x55cc82df28df in pyrun_file Python/pythonrun.c:1208
        #22 0x55cc82df28df in _PyRun_SimpleFileObject Python/pythonrun.c:456
        #23 0x55cc82df3464 in _PyRun_AnyFileObject Python/pythonrun.c:90
        #24 0x55cc82b44f9e in pymain_run_file_obj Modules/main.c:353
        #25 0x55cc82b44f9e in pymain_run_file Modules/main.c:372
        #26 0x55cc82b44f9e in pymain_run_python Modules/main.c:587
        #27 0x55cc82b46743 in Py_RunMain Modules/main.c:666
        #28 0x55cc82b46743 in pymain_main Modules/main.c:696
        #29 0x55cc82b46743 in Py_BytesMain Modules/main.c:720
        #30 0x7fc3a1846189 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
        #31 0x7fc3a1846244 in __libc_start_main_impl ../csu/libc-start.c:381
        #32 0x55cc82b42b60 in _start (/home/kali/python3.10.12/python+0x176b60) (BuildId: 6292689f0cb3a264af4e67751a64a14c9a1caac4)
    
    Address 0x7fc39f9daf34 is located in stack of thread T0 at offset 52 in frame
        #0 0x7fc3a10f363f in iso2022_encode /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:157
    
      This frame has 2 object(s):
        [48, 52) 'c' (line 161) <== Memory access at offset 52 overflows this variable
        [64, 72) 'length' (line 184)
    HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork
          (longjmp and C++ exceptions *are* supported)
    SUMMARY: AddressSanitizer: stack-buffer-overflow /home/kali/python3.10.12/Modules/cjkcodecs/_codecs_iso2022.c:808 in jisx0213_encoder
    Shadow bytes around the buggy address:
      0x7fc39f9dac80: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5
      0x7fc39f9dad00: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5
      0x7fc39f9dad80: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 00 00 00 00
      0x7fc39f9dae00: f1 f1 f1 f1 f8 f2 f2 f2 00 f2 f2 f2 00 00 f3 f3
      0x7fc39f9dae80: f1 f1 f1 f1 00 00 00 00 00 00 00 f3 f3 f3 f3 f3
    =>0x7fc39f9daf00: f1 f1 f1 f1 f1 f1[04]f2 00 f3 f3 f3 00 00 00 00
      0x7fc39f9daf80: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 00 00 00 00
      0x7fc39f9db000: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5
      0x7fc39f9db080: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5
      0x7fc39f9db100: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5
      0x7fc39f9db180: f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 f5 00 00 00 00
    Shadow byte legend (one shadow byte represents 8 application bytes):
      Addressable:           00
      Partially addressable: 01 02 03 04 05 06 07 
      Heap left redzone:       fa
      Freed heap region:       fd
      Stack left redzone:      f1
      Stack mid redzone:       f2
      Stack right redzone:     f3
      Stack after return:      f5
      Stack use after scope:   f8
      Global redzone:          f9
      Global init order:       f6
      Poisoned by user:        f7
      Container overflow:      fc
      Array cookie:            ac
      Intra object redzone:    bb
      ASan internal:           fe
      Left alloca redzone:     ca
      Right alloca redzone:    cb
    ==17275==ABORTING
    

    crashfile.txt

  9. 8 remaining items

  10. added a commit that references this issue on Nov 6, 2023
  11. added a commit that references this issue on Nov 6, 2023
  12. added 3 commits that reference this issue on Nov 6, 2023
  13. added 6 commits that reference this issue on Nov 6, 2023
  14. added a commit that references this issue on Nov 8, 2023
  15. added a commit that references this issue on Feb 11, 2024
  16. added a commit that references this issue on Sep 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions