[
https://issues.apache.org/jira/browse/THRIFT-6099?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dmytro Shteflyuk resolved THRIFT-6099.
--------------------------------------
Fix Version/s: 0.25.0
Resolution: Fixed
> Ruby MemoryBufferTransport should reject invalid read lengths
> -------------------------------------------------------------
>
> Key: THRIFT-6099
> URL: https://issues.apache.org/jira/browse/THRIFT-6099
> Project: Thrift
> Issue Type: Bug
> Components: Ruby - Library
> Reporter: Dmytro Shteflyuk
> Assignee: Dmytro Shteflyuk
> Priority: Major
> Fix For: 0.25.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> h3. Problem
> {{Thrift::MemoryBufferTransport#read}} does not validate a negative length
> before passing it to Ruby string APIs in the native extension. When
> {{thrift_native}} is loaded, calling {{read(-1)}} can terminate the Ruby
> process instead of reporting an invalid request.
> The pure-Ruby implementation also lacks the expected negative-size check. It
> raises an unrelated exception after changing the transport's read position,
> so the native and pure-Ruby implementations do not provide the same contract.
> The native implementation additionally advances its internal index using
> signed integer addition before clamping it to the buffer size. A
> maximum-width read after the index has advanced can overflow that calculation.
> h3. Client impact
> This affects Ruby clients using {{MemoryBufferTransport}}. A negative length
> may terminate a process using the native extension, while the pure-Ruby
> implementation may raise the wrong exception and leave the transport in an
> unexpected state.
> Normal reads with valid lengths are unaffected.
> h3. Reproduction
> With the native extension loaded:
> {code:ruby}
> require "thrift"
> transport = Thrift::MemoryBufferTransport.new("abc")
> transport.read(-1)
> {code}
> The Ruby process may terminate instead of raising a Thrift transport
> exception.
> The boundary calculation can also be exercised with:
> {code:ruby}
> transport = Thrift::MemoryBufferTransport.new("abcd")
> transport.read(1)
> transport.read((2**31) - 1)
> {code}
> h3. Expected behavior
> A negative length should raise {{Thrift::TransportException}} with type
> {{NEGATIVE_SIZE}} and should not consume any input.
> Zero-length, exact-length, oversized, and maximum-width reads should update
> the transport position consistently without overflowing the native index
> calculation. Reads beyond the available data should continue to raise
> {{EOFError}}.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)