Re: [bug report] NULL-pointer deference in GNU_gama::set() in ellipsoid.h

Aleš Čepek <[email protected]> Sun, 7 Apr 2019 17:11:51 +0200
Newsgroups gmane.comp.gnu.gama.bugs
Message-ID <CAGN9seTVDMAmU+UCAmm2D6WtTvnuKp5XVJCa3tVgDp3creSY_w@mail.gmail.com>
--===============3149484254436109376==
Content-Type: multipart/alternative; boundary="00000000000078ec440585f22421"

--00000000000078ec440585f22421
Content-Type: text/plain; charset="UTF-8"

Fixed in gama-2.04 (next version).
ac

On Tue, 2 Apr 2019 at 14:01, wcventure <[email protected]> wrote:

> Hi there,
>
> I have found NULL-pointer deference in GNU_gama::set() in ellipsoid.h,  in
> gama 2.04 the lastest release version. A crafted input can cause segment
> faults and I have confirmed them with address sanitizer too.
>
> Here are the POC files. Please use the "./gama-g3 --algorithm envelope
> $POC ./tmp" to reproduce the bug.
> The ASAN dumps the stack trace as follows:
>
> AddressSanitizer:DEADLYSIGNAL
> =================================================================
> ==188911==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000028 (pc 0x0000006d4c19 bp 0x7ffe67787e50 sp 0x7ffe67787b70 T0)
> ==188911==The signal is caused by a WRITE memory access.
> ==188911==Hint: address points to the zero page.
>     #0 0x6d4c18 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellipsoid) /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42
>     #1 0x63b53e in GNU_gama::DataParser::g3_const_ellipsoid_b(char const*) /gama-2.04/lib/gnu_gama/xml/dataparser_g3.cpp:1223:6
>     #2 0x7fb90df723ea in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x83ea)
>     #3 0x7fb90df733ab in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x93ab)
>     #4 0x7fb90df74ccd in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xaccd)
>     #5 0x7fb90df75424 in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xb424)
>     #6 0x7fb90df7772a in XML_ParseBuffer (/lib/x86_64-linux-gnu/libexpat.so.1+0xd72a)
>     #7 0x51ff33 in GNU_gama::BaseParser<GNU_gama::Exception::parser>::xml_parse(char const*, int, int) /gama-2.04/bin/../lib/gnu_gama/xml/baseparser.h:84:17
>     #8 0x51a340 in main_g3() /gama-2.04/bin/gama-g3.cpp:141:20
>     #9 0x51d64d in main /gama-2.04/bin/gama-g3.cpp:231:14
>     #10 0x7fb90ccea82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291
>     #11 0x41d2b8 in _start (/gama-2.04/build/bin/gama-g3+0x41d2b8)
>
> AddressSanitizer can not provide additional info.
> SUMMARY: AddressSanitizer: SEGV /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellipsoid)
> ==188911==ABORTING
>
> Thanks
>
>
>
> _______________________________________________
> Bug-gama mailing list
> [email protected]
> https://lists.gnu.org/mailman/listinfo/bug-gama
>

--00000000000078ec440585f22421
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Fixed in gama-2.04 (next version).</div><div>ac<br></=
div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_at=
tr">On Tue, 2 Apr 2019 at 14:01, wcventure &lt;<a href=3D"mailto:wcventure@=
126.com">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gma=
il_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,2=
04,204);padding-left:1ex"><div style=3D"line-height:1.7;color:rgb(0,0,0);fo=
nt-size:14px;font-family:Arial"><p class=3D"gmail-m_-8027553413833795642cod=
e-line" style=3D"box-sizing:border-box;margin-top:0px;margin-bottom:16px;co=
lor:rgb(36,41,46);font-family:-apple-system,BlinkMacSystemFont,&quot;Segoe =
UI&quot;,Helvetica,Arial,sans-serif,&quot;Apple Color Emoji&quot;,&quot;Seg=
oe UI Emoji&quot;,&quot;Segoe UI Symbol&quot;;font-size:16px">Hi there,</p>=
<p class=3D"gmail-m_-8027553413833795642code-line gmail-m_-8027553413833795=
642code-active-line" style=3D"box-sizing:border-box;margin-top:0px;margin-b=
ottom:16px;color:rgb(36,41,46);font-family:-apple-system,BlinkMacSystemFont=
,&quot;Segoe UI&quot;,Helvetica,Arial,sans-serif,&quot;Apple Color Emoji&qu=
ot;,&quot;Segoe UI Emoji&quot;,&quot;Segoe UI Symbol&quot;;font-size:16px">=
I have found NULL-pointer deference in GNU_gama::set() in ellipsoid.h,=C2=
=A0 in gama 2.04 the lastest release version. A crafted input can cause seg=
ment faults and I have confirmed them with address sanitizer too.</p><p cla=
ss=3D"gmail-m_-8027553413833795642code-line" style=3D"box-sizing:border-box=
;margin-top:0px;margin-bottom:16px;color:rgb(36,41,46);font-family:-apple-s=
ystem,BlinkMacSystemFont,&quot;Segoe UI&quot;,Helvetica,Arial,sans-serif,&q=
uot;Apple Color Emoji&quot;,&quot;Segoe UI Emoji&quot;,&quot;Segoe UI Symbo=
l&quot;;font-size:16px">Here are the POC files. Please use the &quot;./gama=
-g3 --algorithm envelope $POC ./tmp&quot; to reproduce the bug.</p><div sty=
le=3D"box-sizing:border-box;margin-top:0px;margin-bottom:16px;color:rgb(36,=
41,46);font-family:-apple-system,BlinkMacSystemFont,&quot;Segoe UI&quot;,He=
lvetica,Arial,sans-serif,&quot;Apple Color Emoji&quot;,&quot;Segoe UI Emoji=
&quot;,&quot;Segoe UI Symbol&quot;;font-size:16px">The ASAN dumps the stack=
 trace as follows:</div><div style=3D"box-sizing:border-box;margin-top:0px;=
margin-bottom:16px;color:rgb(36,41,46);font-family:-apple-system,BlinkMacSy=
stemFont,&quot;Segoe UI&quot;,Helvetica,Arial,sans-serif,&quot;Apple Color =
Emoji&quot;,&quot;Segoe UI Emoji&quot;,&quot;Segoe UI Symbol&quot;;font-siz=
e:16px"><pre style=3D"box-sizing:border-box;padding:16px;border-radius:3px;=
overflow:auto;background-color:rgb(246,248,250);color:initial;margin-top:0p=
x;margin-bottom:16px;font-family:SFMono-Regular,Consolas,&quot;Liberation M=
ono&quot;,Menlo,Courier,monospace;font-size:13.6px;line-height:1.45;backgro=
und-image:initial;background-position:initial;background-size:initial;backg=
round-repeat:initial;background-origin:initial;background-clip:initial"><co=
de class=3D"gmail-m_-8027553413833795642code-line" style=3D"color:initial;f=
ont-family:SFMono-Regular,Consolas,&quot;Liberation Mono&quot;,Menlo,Courie=
r,monospace;line-height:inherit;box-sizing:border-box;padding:0px;margin:0p=
x;background:transparent none repeat scroll 0% 0%;border-radius:3px;word-br=
eak:normal;white-space:pre-wrap;border:0px none;display:inline;overflow:vis=
ible"><code style=3D"color:initial;font-family:SFMono-Regular,Consolas,&quo=
t;Liberation Mono&quot;,Menlo,Courier,monospace;font-size:11.56px;line-heig=
ht:inherit;box-sizing:border-box;padding:0px;margin:0px;background-color:tr=
ansparent;border-radius:3px;display:inline;overflow:visible;border:0px none=
"><div style=3D"box-sizing:border-box;background:rgba(0,0,0,0) none repeat =
scroll 0% 0%">AddressSanitizer:DEADLYSIGNAL
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
=3D=3D188911=3D=3DERROR: AddressSanitizer: SEGV on unknown address 0x000000=
000028 (pc 0x0000006d4c19 bp 0x7ffe67787e50 sp 0x7ffe67787b70 T0)
=3D=3D188911=3D=3DThe signal is caused by a WRITE memory access.
=3D=3D188911=3D=3DHint: address points to the zero page.
    #0 0x6d4c18 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellip=
soid) /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42
    #1 0x63b53e in GNU_gama::DataParser::g3_const_ellipsoid_b(char const*) =
/gama-2.04/lib/gnu_gama/xml/dataparser_g3.cpp:1223:6
    #2 0x7fb90df723ea in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x83ea)
    #3 0x7fb90df733ab in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0x93ab)
    #4 0x7fb90df74ccd in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xaccd)
    #5 0x7fb90df75424 in _init (/lib/x86_64-linux-gnu/libexpat.so.1+0xb424)
    #6 0x7fb90df7772a in XML_ParseBuffer (/lib/x86_64-linux-gnu/libexpat.so=
.1+0xd72a)
    #7 0x51ff33 in GNU_gama::BaseParser&lt;GNU_gama::Exception::parser&gt;:=
:xml_parse(char const*, int, int) /gama-2.04/bin/../lib/gnu_gama/xml/basepa=
rser.h:84:17
    #8 0x51a340 in main_g3() /gama-2.04/bin/gama-g3.cpp:141:20
    #9 0x51d64d in main /gama-2.04/bin/gama-g3.cpp:231:14
    #10 0x7fb90ccea82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/=
csu/../csu/libc-start.c:291
    #11 0x41d2b8 in _start (/gama-2.04/build/bin/gama-g3+0x41d2b8)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /gama-2.04/lib/./gnu_gama/ellipsoid.h:45:42=
 in GNU_gama::set(GNU_gama::Ellipsoid*, GNU_gama::gama_ellipsoid)
=3D=3D188911=3D=3DABORTING
</div></code></code></pre><p class=3D"gmail-m_-8027553413833795642code-line=
" style=3D"box-sizing:border-box;margin-top:0px;margin-bottom:16px">Thanks<=
/p></div></div><br><br><span title=3D"neteasefooter"><p>=C2=A0</p></span>__=
_____________________________________________<br>
Bug-gama mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><=
br>
<a href=3D"https://lists.gnu.org/mailman/listinfo/bug-gama" rel=3D"noreferr=
er" target=3D"_blank">https://lists.gnu.org/mailman/listinfo/bug-gama</a><b=
r>
</blockquote></div>

--00000000000078ec440585f22421--


--===============3149484254436109376==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Bug-gama mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/bug-gama

--===============3149484254436109376==--