Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-40492

queue_event: fake ROTATE checksum adjust copies into fixed rot_buf without bounding event_len (stack OOB)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Blocker
    • Resolution: Fixed
    • 13.0.1
    • 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2
    • Replication
    • MariaDB Server 13.0.1 (tag mariadb-13.0.1); also present on main tip. Confirmed by source review on macOS arm64.
    • Can result in hang or crash
    • Hide
      A replica could crash on connecting to a master whose binlog_checksum setting differs from the setting in effect when the replica's relay log was written, if the master's binary log file name was longer than a file name may legally be; the replica did not check the length of the file name the master reported before storing it, so an overlong name corrupted the replica's memory; the replica now rejects the over-sized name and stops its IO thread with an error, instead of crashing
      Show
      A replica could crash on connecting to a master whose binlog_checksum setting differs from the setting in effect when the replica's relay log was written, if the master's binary log file name was longer than a file name may legally be; the replica did not check the length of the file name the master reported before storing it, so an overlong name corrupted the replica's memory; the replica now rejects the over-sized name and stops its IO thread with an error, instead of crashing
    • Q3/2026 Replic. Development

    Description

      In `sql/slave.cc`, `queue_event()` uses a fixed stack buffer for fake ROTATE checksum special-cases:
      ```c
      uchar rot_buf[LOG_EVENT_HEADER_LEN + ROTATE_HEADER_LEN + FN_REFLEN]; /* 539 bytes */
      ```
      On the RSC_1 path (fake Rotate, master checksum OFF, relay-log checksum ON):
      ```c
      if (uint4korr(&buf[0]) == 0 && checksum_alg == BINLOG_CHECKSUM_ALG_OFF &&
      mi->rli.relay_log.relay_log_checksum_alg != BINLOG_CHECKSUM_ALG_OFF)

      { event_len += BINLOG_CHECKSUM_LEN; memcpy(rot_buf, buf, event_len - BINLOG_CHECKSUM_LEN); ... int4store(&rot_buf[event_len - BINLOG_CHECKSUM_LEN], rot_crc); }

      ```
      There is no check that `event_len` fits in `rot_buf`.
      `Rotate_log_event` ctor caps `ident_len` to `FN_REFLEN-1`, but RSC still uses the original `event_len`. A max-sized rotate already makes the final `int4store` write past the 539-byte buffer; a larger fake ROTATE overflows further via `memcpy`.
      RSC_2 (strip checksum) has the same missing bound on `memcpy(rot_buf, buf, event_len)`.

        1. Impact
          Slave IO thread can stack-overflow / crash when queuing a crafted fake ROTATE under checksum policy mismatch.

      Attachments

        Issue Links

          Activity

            People

              bnestere Brandon Nesterenko
              sxt shixin tan
              Brandon Nesterenko Brandon Nesterenko
              Kristian Nielsen Kristian Nielsen
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 1d
                  1d
                  Remaining:
                  Remaining Estimate - 0d
                  0d
                  Logged:
                  Time Spent - 4.5h Time Not Required
                  4.5h

                  Git Integration

                    Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.