In this code in ma_read_ok_packet() at line 2691 (and two other places):
plen= net_field_length(&pos);
|
if (pos + plen > end)
|
goto corrupted;
|
data2.str= (char *)pos;
|
data2.length= plen;
|
If net_field_length() returns a large enough length, pos + plen will
wrap, and the "if" won't spot a problem.
One possible down-stream consequence is that ma_save_session_track()'s
memcpy(str->str, data2->str, data2->length);
|
will pass that huge length to memcpy(), causing it to do something bad.
The preceding call to ma_multi_malloc() won't neccessarily fail and
prevent this, because a huge data2->length can cause the total length
calculated by ma_multi_malloc() to wrap to something that won't cause
malloc() to fail.
I've attached a fake DB server that tickles this bug.
$ cc mc4a.c
|
$ ./a.out &
|
$ mariadb --version
|
maria/build/client/mariadb from 11.6.0-MariaDB, client 15.2 for Linux (x86_64) using readline 5.1
|
$ mariadb --host=127.0.0.1 --ssl=OFF
|
Segmentation fault (core dumped)
|
Here's what gdb says:
Program received signal SIGSEGV, Segmentation fault.
|
0x00005555555e2ae6 in list_add (root=0x555555b4e960, element=0x555555b4e990) at /home/rtm/maria/server/libmariadb/libmariadb/ma_list.c:34
|
warning: Source file is more recent than executable.
|
34 root->prev->next= element;
|
(gdb) where
|
#0 0x00005555555e2ae6 in list_add (root=0x555555b4e960, element=0x555555b4e990) at /home/rtm/maria/server/libmariadb/libmariadb/ma_list.c:34
|
#1 0x00005555555db65a in ma_save_session_track_info (ptr=0x555555af3000 <mysql>, type=SESSION_TRACK_TYPE)
|
at /home/rtm/maria/server/libmariadb/libmariadb/mariadb_lib.c:2578
|
#2 0x00005555555dbcbd in ma_read_ok_packet (mysql=0x555555af3000 <mysql>, pos=0x555555b4ee31 "", length=64)
|
at /home/rtm/maria/server/libmariadb/libmariadb/mariadb_lib.c:2697
|
#3 0x0000555555601487 in run_plugin_auth (mysql=0x555555af3000 <mysql>, data=0x555555b4ee47 "", data_len=21, data_plugin=0x555555b4ee5c "", db=0x0)
|
at /home/rtm/maria/server/libmariadb/plugins/auth/my_auth.c:782
|
#4 0x00005555555d9647 in mthd_my_real_connect (mysql=0x555555af3000 <mysql>, host=0x555555b459f8 "127.0.0.1", user=0x5555556b0285 "",
|
passwd=0x5555556b0285 "", db=0x0, port=3306, unix_socket=0x0, client_flag=541131904)
|
at /home/rtm/maria/server/libmariadb/libmariadb/mariadb_lib.c:1973
|
#5 0x00005555555d7f3f in mysql_real_connect (mysql=0x555555af3000 <mysql>, host=0x555555b459f8 "127.0.0.1", user=0x0, passwd=0x0, db=0x0, port=0,
|
unix_socket=0x0, client_flag=536937472) at /home/rtm/maria/server/libmariadb/libmariadb/mariadb_lib.c:1513
|
#6 0x00005555555c3b3d in do_connect (mysql=0x555555af3000 <mysql>, host=0x555555b459f8 "127.0.0.1", user=0x0, password=0x0, database=0x0,
|
flags=536937472) at /home/rtm/maria/server/client/mysql.cc:1523
|
#7 0x00005555555ccec7 in sql_real_connect (host=0x555555b459f8 "127.0.0.1", database=0x0, user=0x0, password=0x0, silent=0)
|
at /home/rtm/maria/server/client/mysql.cc:4977
|
#8 0x00005555555cd0d9 in sql_connect (host=0x555555b459f8 "127.0.0.1", database=0x0, user=0x0, password=0x0, silent=0)
|
at /home/rtm/maria/server/client/mysql.cc:5034
|
#9 0x00005555555c2fe3 in main (argc=11, argv=0x555555b453e0) at /home/rtm/maria/server/client/mysql.cc:1303
|
valgrind catches the offending memcpy():
Invalid write of size 1
|
at 0x48500E3: memmove (in /usr/libexec/valgrind/vgpreload_memcheck-amd64-linux.so)
|
by 0x18F5EF: ma_save_session_track_info (mariadb_lib.c:2575)
|
by 0x18FCBC: ma_read_ok_packet (mariadb_lib.c:2697)
|
by 0x1B5486: run_plugin_auth (my_auth.c:782)
|
by 0x18D646: mthd_my_real_connect (mariadb_lib.c:1973)
|
by 0x18BF3E: mysql_real_connect (mariadb_lib.c:1513)
|
by 0x177B3C: do_connect(st_mysql*, char const*, char const*, char const*, char const*, unsigned long) (mysql.cc:1523)
|
by 0x180EC6: sql_real_connect(char*, char*, char*, char*, unsigned int) (mysql.cc:4977)
|
by 0x1810D8: sql_connect(char*, char*, char*, char*, unsigned int) (mysql.cc:5034)
|
by 0x176FE2: main (mysql.cc:1303)
|
Address 0x55b28c8 is 0 bytes after a block of size 40 alloc'd
|
at 0x4845828: malloc (in /usr/libexec/valgrind/vgpreload_memcheck-amd64-linux.so)
|
by 0x198E62: ma_multi_malloc (ma_alloc.c:183)
|
by 0x18F599: ma_save_session_track_info (mariadb_lib.c:2567)
|
by 0x18FCBC: ma_read_ok_packet (mariadb_lib.c:2697)
|
by 0x1B5486: run_plugin_auth (my_auth.c:782)
|
by 0x18D646: mthd_my_real_connect (mariadb_lib.c:1973)
|
by 0x18BF3E: mysql_real_connect (mariadb_lib.c:1513)
|
by 0x177B3C: do_connect(st_mysql*, char const*, char const*, char const*, char const*, unsigned long) (mysql.cc:1523)
|
by 0x180EC6: sql_real_connect(char*, char*, char*, char*, unsigned int) (mysql.cc:4977)
|
by 0x1810D8: sql_connect(char*, char*, char*, char*, unsigned int) (mysql.cc:5034)
|
by 0x176FE2: main (mysql.cc:1303)
|
There are no comments yet on this issue.
{"report":{"fcp":1162.5,"ttfb":289.30000019073486,"pageVisibility":"visible","entityId":129655,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"8da443e8-4681-4409-ad6c-4f0b92da7acc","navigationType":0,"readyForUser":1277.2000002861023,"redirectCount":0,"resourceLoadedEnd":1445.3000001907349,"resourceLoadedStart":306.80000019073486,"resourceTiming":[{"duration":337.09999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":306.80000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":306.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":643.9000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":337.2000002861023,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":307,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":307,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":644.2000002861023,"responseStart":0,"secureConnectionStart":0},{"duration":346.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":307.2000002861023,"connectEnd":307.2000002861023,"connectStart":307.2000002861023,"domainLookupEnd":307.2000002861023,"domainLookupStart":307.2000002861023,"fetchStart":307.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":307.2000002861023,"responseEnd":653.7000002861023,"responseStart":653.7000002861023,"secureConnectionStart":307.2000002861023},{"duration":424.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":307.40000009536743,"connectEnd":307.40000009536743,"connectStart":307.40000009536743,"domainLookupEnd":307.40000009536743,"domainLookupStart":307.40000009536743,"fetchStart":307.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":307.40000009536743,"responseEnd":731.8000001907349,"responseStart":731.8000001907349,"secureConnectionStart":307.40000009536743},{"duration":428.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":307.7000002861023,"connectEnd":307.7000002861023,"connectStart":307.7000002861023,"domainLookupEnd":307.7000002861023,"domainLookupStart":307.7000002861023,"fetchStart":307.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":307.7000002861023,"responseEnd":735.8000001907349,"responseStart":735.8000001907349,"secureConnectionStart":307.7000002861023},{"duration":428.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":307.80000019073486,"connectEnd":307.80000019073486,"connectStart":307.80000019073486,"domainLookupEnd":307.80000019073486,"domainLookupStart":307.80000019073486,"fetchStart":307.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":307.80000019073486,"responseEnd":736.3000001907349,"responseStart":736.3000001907349,"secureConnectionStart":307.80000019073486},{"duration":428.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":308,"connectEnd":308,"connectStart":308,"domainLookupEnd":308,"domainLookupStart":308,"fetchStart":308,"redirectEnd":0,"redirectStart":0,"requestStart":308,"responseEnd":736.7000002861023,"responseStart":736.7000002861023,"secureConnectionStart":308},{"duration":494.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":308.1000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":308.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":802.7000002861023,"responseStart":0,"secureConnectionStart":0},{"duration":428.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":308.2000002861023,"connectEnd":308.2000002861023,"connectStart":308.2000002861023,"domainLookupEnd":308.2000002861023,"domainLookupStart":308.2000002861023,"fetchStart":308.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":308.2000002861023,"responseEnd":737.1000003814697,"responseStart":737.1000003814697,"secureConnectionStart":308.2000002861023},{"duration":494.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":308.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":308.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":802.9000000953674,"responseStart":0,"secureConnectionStart":0},{"duration":429.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":308.6000003814697,"connectEnd":308.6000003814697,"connectStart":308.6000003814697,"domainLookupEnd":308.6000003814697,"domainLookupStart":308.6000003814697,"fetchStart":308.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":308.6000003814697,"responseEnd":737.7000002861023,"responseStart":737.7000002861023,"secureConnectionStart":308.6000003814697},{"duration":1118.5999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":309.40000009536743,"connectEnd":309.40000009536743,"connectStart":309.40000009536743,"domainLookupEnd":309.40000009536743,"domainLookupStart":309.40000009536743,"fetchStart":309.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":309.40000009536743,"responseEnd":1428,"responseStart":1428,"secureConnectionStart":309.40000009536743},{"duration":1119.2999997138977,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":309.6000003814697,"connectEnd":309.6000003814697,"connectStart":309.6000003814697,"domainLookupEnd":309.6000003814697,"domainLookupStart":309.6000003814697,"fetchStart":309.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":309.6000003814697,"responseEnd":1428.9000000953674,"responseStart":1428.9000000953674,"secureConnectionStart":309.6000003814697},{"duration":218,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":855.1000003814697,"connectEnd":855.1000003814697,"connectStart":855.1000003814697,"domainLookupEnd":855.1000003814697,"domainLookupStart":855.1000003814697,"fetchStart":855.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":855.1000003814697,"responseEnd":1073.1000003814697,"responseStart":1073.1000003814697,"secureConnectionStart":855.1000003814697},{"duration":320,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1112.1000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1112.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1432.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":325.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":1113,"connectEnd":1113,"connectStart":1113,"domainLookupEnd":1113,"domainLookupStart":1113,"fetchStart":1113,"redirectEnd":0,"redirectStart":0,"requestStart":1113,"responseEnd":1438.4000000953674,"responseStart":1438.4000000953674,"secureConnectionStart":1113},{"duration":331.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/097ae97cb8fbec7d6ea4bbb1f26955b9-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":1113.4000000953674,"connectEnd":1113.4000000953674,"connectStart":1113.4000000953674,"domainLookupEnd":1113.4000000953674,"domainLookupStart":1113.4000000953674,"fetchStart":1113.4000000953674,"redirectEnd":0,"redirectStart":0,"requestStart":1113.4000000953674,"responseEnd":1445.3000001907349,"responseStart":1445.3000001907349,"secureConnectionStart":1113.4000000953674}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":104,"responseStart":290,"responseEnd":292,"domLoading":305,"domInteractive":1453,"domContentLoadedEventStart":1453,"domContentLoadedEventEnd":1497,"domComplete":2220,"loadEventStart":2220,"loadEventEnd":2221,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1435.5},{"name":"bigPipe.sidebar-id.end","time":1436.4000000953674},{"name":"bigPipe.activity-panel-pipe-id.start","time":1436.7000002861023},{"name":"bigPipe.activity-panel-pipe-id.end","time":1437.2000002861023},{"name":"activityTabFullyLoaded","time":1504.3000001907349}],"measures":[],"correlationId":"9dea2cf63daca9","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":117,"dbReadsTimeInMs":10,"dbConnsTimeInMs":19,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}