Details
-
Bug
-
Status: Closed (View Workflow)
-
Blocker
-
Resolution: Fixed
-
10.11, 11.4, 11.8, 12.3, 13.0
-
Can result in hang or crash
-
Fix memory disclosure (if not a crash) with v2 Rows Events with truncated extra data
-
Q3/2026 Replic. Development
Description
|
CS 13.0.1 3a2f8e27981b76b99d2b87cc3bcec5ef022b2b23 (Optimized, UBASAN, Clang 21.1.3-20250923) Build 10/04/2026 |
==396829==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x7601a8e20870 at pc 0x5c6dbf3958bf bp 0x7fff44dc74f0 sp 0x7fff44dc6cb0
|
READ of size 255 at 0x7601a8e20870 thread T0
|
#0 0x5c6dbf3958be in __asan_memcpy (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x6cc8be) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#1 0x5c6dbf448167 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x77f167) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#2 0x5c6dbf44ca6d (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x783a6d) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#3 0x5c6dbf435425 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x76c425) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#4 0x5c6dbf3ddc62 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x714c62) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#5 0x5c6dbf434499 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x76b499) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#6 0x5c6dbf3ee403 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x725403) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#7 0x7911aa02a1c9 in __libc_start_call_main csu/../sysdeps/nptl/libc_start_call_main.h:58:16
|
#8 0x7911aa02a28a in __libc_start_main csu/../csu/libc-start.c:360:3
|
#9 0x5c6dbf2f24f4 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x6294f4) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
|
|
0x7601a8e20870 is located 0 bytes after 176-byte region [0x7601a8e207c0,0x7601a8e20870)
|
allocated by thread T0 here:
|
#0 0x5c6dbf397c68 in malloc (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x6cec68) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#1 0x5c6dbf6825a8 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x9b95a8) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#2 0x5c6dbf46d1a2 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x7a41a2) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#3 0x5c6dbf48dede (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x7c4ede) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#4 0x5c6dbf48e079 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x7c5079) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#5 0x5c6dbf433589 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x76a589) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#6 0x5c6dbf431f58 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x768f58) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#7 0x5c6dbf434409 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x76b409) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#8 0x5c6dbf3ee403 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x725403) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
#9 0x7911aa02a1c9 in __libc_start_call_main csu/../sysdeps/nptl/libc_start_call_main.h:58:16
|
#10 0x7911aa02a28a in __libc_start_main csu/../csu/libc-start.c:360:3
|
#11 0x5c6dbf2f24f4 (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x6294f4) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8)
|
|
|
SUMMARY: AddressSanitizer: heap-buffer-overflow (/test/UBASAN_MD100426-mariadb-13.0.1-linux-x86_64-opt/bin/mariadb-binlog+0x6cc8be) (BuildId: e043b33f3bfe237745152dadcbf1ec22fc6fe2b8) in __asan_memcpy
|
Shadow bytes around the buggy address:
|
0x7601a8e20580: fd fd fd fa fa fa fa fa fa fa fa fa fd fd fd fd
|
0x7601a8e20600: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
|
0x7601a8e20680: fd fd fa fa fa fa fa fa fa fa fd fd fd fd fd fd
|
0x7601a8e20700: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fa
|
0x7601a8e20780: fa fa fa fa fa fa fa fa 00 00 00 00 00 00 00 00
|
=>0x7601a8e20800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00[fa]fa
|
0x7601a8e20880: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x7601a8e20900: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x7601a8e20980: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x7601a8e20a00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
0x7601a8e20a80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
|
Shadow byte legend (one shadow byte represents 8 application bytes):
|
Addressable: 00
|
Partially addressable: 01 02 03 04 05 06 07
|
Heap left redzone: fa
|
Freed heap region: fd
|
Stack left redzone: f1
|
Stack mid redzone: f2
|
Stack right redzone: f3
|
Stack after return: f5
|
Stack use after scope: f8
|
Global redzone: f9
|
Global init order: f6
|
Poisoned by user: f7
|
Container overflow: fc
|
Array cookie: ac
|
Intra object redzone: bb
|
ASan internal: fe
|
Left alloca redzone: ca
|
Right alloca redzone: cb
|
==396829==ABORTING
|
Attachments
Issue Links
- is blocked by
-
MDEV-40542 MSAN use-of-uninitialized-value on Unknown_log_event::read_checksum_alg
-
- Closed
-
- is caused by
-
MDEV-5115 RBR from MySQL 5.6 to MariaDB 10.0 does not work
-
- Closed
-
- relates to
-
MDEV-39689 Slave Overflow on Malformed Table_map_log_event
-
- Closed
-
-
MDEV-40365 OOB read for common_header_len & post_header_len on malformed Format_description_log_event
-
- Closed
-
-
MDEV-40366 OOB read for used_checksum_alg on malformed Format_description_log_event
-
- Closed
-
-
MDEV-40492 queue_event: fake ROTATE checksum adjust copies into fixed rot_buf without bounding event_len (stack OOB)
-
- Closed
-
- split to
-
MDEV-40487 OOB read in parser constructor on malformed Rows_log_event
-
- Open
-
-
MDEV-40542 MSAN use-of-uninitialized-value on Unknown_log_event::read_checksum_alg
-
- Closed
-