apache / apache/iceberg-python
Cython Avro decoder reads past the buffer end on malformed input
- Ngôn ngữ chính
- Python
- Star
- 1.1k
- Fork
- 581
- Merge trung bình
- 1 ngày 17 giờ
- Pull request đã merge (30 ngày)
- 78
Mô tả
Two places in `pyiceberg/avro/decoder_fast.pyx` advance the read pointer using a value taken from the stream, without bounding it against `self._end`.
**1. `read_bytes` does not validate the decoded length**
```python
cpdef inline bytes read_bytes(self):
cdef uint64_t length;
if self._current >= self._end: # only confirms 1 byte is available
raise EOFError(f"EOF: read 1 bytes")
decode_zigzag_ints(&self._current, 1, &length)
if length <= 0:
return b""
cdef const unsigned char *r = self._current
self._current += length # not checked against self._end
return r[0:length]
```
The guard confirms one byte is available before decoding the length, but the decoded `length` is then used to slice and to advance `_current` with no check that `_current + length <= _end`. A length field larger than the remaining buffer reads beyond it.
**2. `decode_zigzag_ints` has no end pointer to bound against**
```c
void decode_zigzag_ints(const unsigned char **buffer, const uint64_t count, uint64_t *result);
```
The signature takes a buffer and a count but no end, so the varint walk cannot stop at the buffer boundary — a run of bytes with the continuation bit set keeps advancing. It is called from five sites in the decoder (lines 93, 101, 111, 124, 176), including from `read_bytes` above.
Both are reachable from a malformed or hostile Avro manifest.
---
Issue investigation generated via claude, reviewed by Sung, Kevin, Fokko.
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Hướng nghiên cứu
Bắt đầu trong pyiceberg/avro/decoder_fast.pyx, đọc read_bytes và decode_zigzag_ints cùng với năm điểm gọi được liệt kê trong issue. Kiểm thử đầu vào Avro sai định dạng hoặc bị cắt ngắn thông qua bộ giải mã. Công việc được hoàn tất khi đầu vào sai định dạng không thể tiến vượt quá cuối bộ đệm và việc giải mã hợp lệ vẫn được bao phủ bởi hành vi hiện có của bộ giải mã.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- security
- Loại issue
- Lỗi
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức phù hợp với người mới
- 72/100