-
-
Notifications
You must be signed in to change notification settings - Fork 246
Expand file tree
/
Copy pathCVE-2022-24795.yml
More file actions
46 lines (36 loc) · 1.62 KB
/
Copy pathCVE-2022-24795.yml
File metadata and controls
46 lines (36 loc) · 1.62 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
---
gem: yajl-ruby
cve: 2022-24795
ghsa: jj47-x69x-mxrm
url: https://github.com/brianmario/yajl-ruby/security/advisories/GHSA-jj47-x69x-mxrm
title: Reallocation bug can trigger heap memory corruption
date: 2022-04-05
description: |
The 1.x branch and the 2.x branch of [yajl](https://github.com/lloyd/yajl)
contain an integer overflow which leads to subsequent heap memory corruption
when dealing with large (~2GB) inputs.
### Details
The [reallocation logic at yajl_buf.c#L64](https://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64)
may result in the `need` 32bit integer wrapping to 0 when `need` approaches
a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation
of buf->alloc into a small heap chunk.
These integers are declared as `size_t` in the 2.x branch of `yajl`, which
practically prevents the issue from triggering on 64bit platforms, however
this does not preclude this issue triggering on 32bit builds on which
`size_t` is a 32bit integer.
Subsequent population of this under-allocated heap chunk is based on the
original buffer size, leading to heap memory corruption.
### Impact
We rate this as a moderate severity vulnerability which mostly impacts
process availability as we believe exploitation for arbitrary code
execution to be unlikely.
### Patches
Patched in yajl-ruby 1.4.2
### Workarounds
Avoid passing large inputs to YAJL
cvss_v3: 5.9
patched_versions:
- ">= 1.4.2"
related:
url:
- https://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64