[
https://issues.apache.org/jira/browse/AVRO-4344?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated AVRO-4344:
---------------------------------
Labels: pull-request-available (was: )
> [C] avro_schema_enum_get returns an uninitialized pointer for an out-of-range
> enum index
> ----------------------------------------------------------------------------------------
>
> Key: AVRO-4344
> URL: https://issues.apache.org/jira/browse/AVRO-4344
> Project: Apache Avro
> Issue Type: Bug
> Components: c
> Reporter: Ismaël Mejía
> Priority: Major
> Labels: pull-request-available
> Fix For: 1.13.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> {{avro_schema_enum_get()}} (lang/c/src/schema.c:534) calls {{st_lookup()}}
> but ignores its return value:
> {code:c}
> const char *avro_schema_enum_get(const avro_schema_t enump, int index)
> {
> union {
> st_data_t data;
> char *sym;
> } val;
> st_lookup(avro_schema_to_enum(enump)->symbols, index, &val.data);
> return val.sym; /* val.sym is uninitialized when st_lookup() fails */
> }
> {code}
> When decoding binary data, the enum ordinal is read directly from the input
> as a {{long}} and passed through without checking it against the number of
> declared symbols (lang/c/src/value-read.c:330, the {{AVRO_ENUM}} case ->
> {{avro_value_set_enum}}).
> If the ordinal is out of range - for example from a malformed or truncated
> container file - {{st_lookup()}} (lang/c/src/st.c:235) returns 0 without
> writing to {{val.data}}, so {{avro_schema_enum_get()}} returns an
> uninitialized stack value as a {{char *}}. A caller that then uses that
> pointer (e.g. {{avropipe}} calling {{strlen()}} on the returned symbol name)
> reads through an indeterminate pointer and typically crashes with SIGSEGV on
> a default CMake Release build.
> *Steps to reproduce:* change the enum ordinal in a small Avro container file
> to a value outside the schema's symbol range and read it with {{avropipe}}
> (or any reader that resolves the symbol name).
> *Affected:* 1.12.0 and current main (both functions are byte-identical).
> *Suggested fix:*
> * Validate the decoded enum index against the number of symbols when reading,
> and return a normal EINVAL/parse error for an out-of-range index instead of
> continuing.
> * Make {{avro_schema_enum_get()}} check the {{st_lookup()}} return value and
> return NULL (callers handling NULL) rather than an uninitialized pointer.
> Reported by Mahdi Alhakim.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)