Re: [bug report] NULL-pointer deference in GNU_gama::set() in ellipsoid.h
Aleš Čepek <[email protected]> Sun, 7 Apr 2019 17:11:51 +0200
| Newsgroups | gmane.comp.gnu.gama.bugs |
|---|---|
| Message-ID | <CAGN9seTVDMAmU+UCAmm2D6WtTvnuKp5XVJCa3tVgDp3creSY_w@mail.gmail.com> |
--===============3149484254436109376== Content-Type: multipart/alternative; boundary="00000000000078ec440585f22421" --00000000000078ec440585f22421 Content-Type: text/plain; charset="UTF-8" Fixed in gama-2.04 (next version). ac On Tue, 2 Apr 2019 at 14:01, wcventure <[email protected]> wrote: > Hi there, > > I have found NULL-pointer deference in GNU_gama::set() in ellipsoid.h, in > gama 2.04 the lastest release version. A crafted input can cause segment > faults and I have confirmed them with address sanitizer too. > > Here are the POC files. Please use the "./gama-g3 --algorithm envelope > $POC ./tmp" to reproduce the bug. > The ASAN dumps the stack trace as follows: > > AddressSanitizer:DEADLYSIGNAL > ================================================================= > ==188911==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000028 (pc 0x0000006d4c19 bp 0x7ffe67787e50 sp 0x7ffe67787b70 T0) > ==188911==The signal is caused by a WRITE memory access. > ==188911==Hint: address points to the zero page. > #0 0x6d4c18 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellipsoid) /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42 > #1 0x63b53e in GNU_gama::DataParser::g3_const_ellipsoid_b(char const*) /gama-2.04/lib/gnu_gama/xml/dataparser_g3.cpp:1223:6 > #2 0x7fb90df723ea in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x83ea) > #3 0x7fb90df733ab in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x93ab) > #4 0x7fb90df74ccd in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xaccd) > #5 0x7fb90df75424 in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xb424) > #6 0x7fb90df7772a in XML_ParseBuffer (/lib/x86_64-linux-gnu/libexpat.so.1+0xd72a) > #7 0x51ff33 in GNU_gama::BaseParser<GNU_gama::Exception::parser>::xml_parse(char const*, int, int) /gama-2.04/bin/../lib/gnu_gama/xml/baseparser.h:84:17 > #8 0x51a340 in main_g3() /gama-2.04/bin/gama-g3.cpp:141:20 > #9 0x51d64d in main /gama-2.04/bin/gama-g3.cpp:231:14 > #10 0x7fb90ccea82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291 > #11 0x41d2b8 in _start (/gama-2.04/build/bin/gama-g3+0x41d2b8) > > AddressSanitizer can not provide additional info. > SUMMARY: AddressSanitizer: SEGV /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellipsoid) > ==188911==ABORTING > > Thanks > > > > _______________________________________________ > Bug-gama mailing list > [email protected] > https://lists.gnu.org/mailman/listinfo/bug-gama > --00000000000078ec440585f22421 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Fixed in gama-2.04 (next version).</div><div>ac<br></= div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_at= tr">On Tue, 2 Apr 2019 at 14:01, wcventure <<a href=3D"mailto:wcventure@= 126.com">[email protected]</a>> wrote:<br></div><blockquote class=3D"gma= il_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,2= 04,204);padding-left:1ex"><div style=3D"line-height:1.7;color:rgb(0,0,0);fo= nt-size:14px;font-family:Arial"><p class=3D"gmail-m_-8027553413833795642cod= e-line" style=3D"box-sizing:border-box;margin-top:0px;margin-bottom:16px;co= lor:rgb(36,41,46);font-family:-apple-system,BlinkMacSystemFont,"Segoe = UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Seg= oe UI Emoji","Segoe UI Symbol";font-size:16px">Hi there,</p>= <p class=3D"gmail-m_-8027553413833795642code-line gmail-m_-8027553413833795= 642code-active-line" style=3D"box-sizing:border-box;margin-top:0px;margin-b= ottom:16px;color:rgb(36,41,46);font-family:-apple-system,BlinkMacSystemFont= ,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji&qu= ot;,"Segoe UI Emoji","Segoe UI Symbol";font-size:16px">= I have found NULL-pointer deference in GNU_gama::set() in ellipsoid.h,=C2= =A0 in gama 2.04 the lastest release version. A crafted input can cause seg= ment faults and I have confirmed them with address sanitizer too.</p><p cla= ss=3D"gmail-m_-8027553413833795642code-line" style=3D"box-sizing:border-box= ;margin-top:0px;margin-bottom:16px;color:rgb(36,41,46);font-family:-apple-s= ystem,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,&q= uot;Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbo= l";font-size:16px">Here are the POC files. Please use the "./gama= -g3 --algorithm envelope $POC ./tmp" to reproduce the bug.</p><div sty= le=3D"box-sizing:border-box;margin-top:0px;margin-bottom:16px;color:rgb(36,= 41,46);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",He= lvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji= ","Segoe UI Symbol";font-size:16px">The ASAN dumps the stack= trace as follows:</div><div style=3D"box-sizing:border-box;margin-top:0px;= margin-bottom:16px;color:rgb(36,41,46);font-family:-apple-system,BlinkMacSy= stemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color = Emoji","Segoe UI Emoji","Segoe UI Symbol";font-siz= e:16px"><pre style=3D"box-sizing:border-box;padding:16px;border-radius:3px;= overflow:auto;background-color:rgb(246,248,250);color:initial;margin-top:0p= x;margin-bottom:16px;font-family:SFMono-Regular,Consolas,"Liberation M= ono",Menlo,Courier,monospace;font-size:13.6px;line-height:1.45;backgro= und-image:initial;background-position:initial;background-size:initial;backg= round-repeat:initial;background-origin:initial;background-clip:initial"><co= de class=3D"gmail-m_-8027553413833795642code-line" style=3D"color:initial;f= ont-family:SFMono-Regular,Consolas,"Liberation Mono",Menlo,Courie= r,monospace;line-height:inherit;box-sizing:border-box;padding:0px;margin:0p= x;background:transparent none repeat scroll 0% 0%;border-radius:3px;word-br= eak:normal;white-space:pre-wrap;border:0px none;display:inline;overflow:vis= ible"><code style=3D"color:initial;font-family:SFMono-Regular,Consolas,&quo= t;Liberation Mono",Menlo,Courier,monospace;font-size:11.56px;line-heig= ht:inherit;box-sizing:border-box;padding:0px;margin:0px;background-color:tr= ansparent;border-radius:3px;display:inline;overflow:visible;border:0px none= "><div style=3D"box-sizing:border-box;background:rgba(0,0,0,0) none repeat = scroll 0% 0%">AddressSanitizer:DEADLYSIGNAL =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D188911=3D=3DERROR: AddressSanitizer: SEGV on unknown address 0x000000= 000028 (pc 0x0000006d4c19 bp 0x7ffe67787e50 sp 0x7ffe67787b70 T0) =3D=3D188911=3D=3DThe signal is caused by a WRITE memory access. =3D=3D188911=3D=3DHint: address points to the zero page. #0 0x6d4c18 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellip= soid) /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42 #1 0x63b53e in GNU_gama::DataParser::g3_const_ellipsoid_b(char const*) = /gama-2.04/lib/gnu_gama/xml/dataparser_g3.cpp:1223:6 #2 0x7fb90df723ea in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x83ea) #3 0x7fb90df733ab in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x93ab) #4 0x7fb90df74ccd in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xaccd) #5 0x7fb90df75424 in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xb424) #6 0x7fb90df7772a in XML_ParseBuffer (/lib/x86_64-linux-gnu/libexpat.so= .1+0xd72a) #7 0x51ff33 in GNU_gama::BaseParser<GNU_gama::Exception::parser>:= :xml_parse(char const*, int, int) /gama-2.04/bin/../lib/gnu_gama/xml/basepa= rser.h:84:17 #8 0x51a340 in main_g3() /gama-2.04/bin/gama-g3.cpp:141:20 #9 0x51d64d in main /gama-2.04/bin/gama-g3.cpp:231:14 #10 0x7fb90ccea82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/= csu/../csu/libc-start.c:291 #11 0x41d2b8 in _start (/gama-2.04/build/bin/gama-g3+0x41d2b8) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42= in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellipsoid) =3D=3D188911=3D=3DABORTING </div></code></code></pre><p class=3D"gmail-m_-8027553413833795642code-line= " style=3D"box-sizing:border-box;margin-top:0px;margin-bottom:16px">Thanks<= /p></div></div><br><br><span title=3D"neteasefooter"><p>=C2=A0</p></span>__= _____________________________________________<br> Bug-gama mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><= br> <a href=3D"https://lists.gnu.org/mailman/listinfo/bug-gama" rel=3D"noreferr= er" target=3D"_blank">https://lists.gnu.org/mailman/listinfo/bug-gama</a><b= r> </blockquote></div> --00000000000078ec440585f22421-- --===============3149484254436109376== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Bug-gama mailing list [email protected] https://lists.gnu.org/mailman/listinfo/bug-gama --===============3149484254436109376==--