apache / apache/arrow-java

Out-of-bounds read for corrupt view offsets in BaseVariableWidthViewVector

未關閉
#1,217 0 則留言 0 個 reaction 已指派 0 人 已被 @lidavidm 認領 在 GitHub 檢視
主要語言
Java
星號
94
分支
152
平均合併
3 天 16 小時
30 天內合併 PR
11

描述

### Describe the bug

`ViewVarCharVector`/`ViewVarBinaryVector` store values longer than `INLINE_SIZE` (12 bytes) out of line, encoding a data-buffer index and an offset inline in the view buffer. When a vector is loaded from an IPC stream these fields come straight from the input.

`BaseVariableWidthViewVector` dereferences them verbatim in `getData`, `getDataPointer`, `hashCode`, `copyFromNotNull` and `splitAndTransferViewBufferAndDataBuffer`, e.g.

```java
dataBuffers.get(bufferIndex).getBytes(dataOffset, result, 0, dataLength);
```

Nothing checks that `bufferIndex` is in range or that `dataOffset + dataLength` fits inside the referenced data buffer. A crafted view whose offset/length points past the data buffer produces an out-of-bounds read: with the default bounds checking it throws `IndexOutOfBoundsException`, but with `arrow.enable_unsafe_memory_access=true` (commonly set in production) it reads arbitrary native heap into the returned value.

### Component(s)

Java

貢獻指南

開啟貢獻指南

研究方向

從 BaseVariableWidthViewVector 開始,檢查 getData、getDataPointer、hashCode、copyFromNotNull 和 splitAndTransferViewBufferAndDataBuffer 中對 out-of-line view 的處理。比較連結的 pull request,然後驗證損壞的 buffer 索引和 offset/length 範圍不再允許越界讀取,包括啟用 unsafe memory access 的情況。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
描述清楚
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。