[System.Private.Xml] Possible incorrect behavior in character counting ( maxCharsCount >= charsCount )
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Start in src/libraries/System.Private.Xml/src/System/Xml/Core/XmlTextReaderImpl.cs at the Debug.Assert on line 3626, using the linked corpus_file_for_xml_crash.txt and the provided SharpFuzz reproduction. Build .NET v6.0.36 in Debug mode with asserts enabled and run the XML reader loop. Done means the corpus no longer causes the maxCharsCount and charsCount assertion to fail.
Written by the indexing model from the issue text.
Description
Description
Hello! I decided to test System.Private.Xml module via fuzzing test.
After some time I found test case which fails Debug.Assert(maxCharsCount >= charsCount)
Reproduction Steps
Download latest .NET v6.0.36 and build it in Debug mode (enable asserts), make reference in test project.
Test's project code:
using SharpFuzz;
using System.Xml;
Fuzzer.Run(stream =>
{
try
{
using (var xml = XmlReader.Create(stream))
{
while (xml.Read()) { }
}
}
catch (XmlException) { }
}
);
In result, value of maxCharsCount is 80 and charsCount is 81 - that produce a crash
Expected behavior
No any crash, as usual
Actual behavior
Debug.Assert(maxCharsCount >= charsCount) is failed because 80 >= 81 is false
Regression?
No response
Known Workarounds
No response
Configuration
.NET v6.0.36 from github, Debug build (enable asserts), Linux Ubuntu x64
Other information
No response
- Dominant language
- C#
- Stars
- 18.3k
- Forks
- 5.6k
- PR merge metrics
- PR metrics pending
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/runtime
-
agentic-workflows untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
area-System.Reflection blocking-clean-ci-optional Known Build Error os-mac-os-x untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
area-CodeGen-coreclr untriaged
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 78/100
-
area-VM-meta-mono untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
:watch: Not Triaged 11.0 fundamentals/subsvc
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
dotnet/AspNetCore.Docs#37699 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SubtitleEdit/subtitleedit#15108 · 1 comment ·
-
area/docs-content Bug pulumi/docs
Difficulty 1/5 1-3 hours Newbie friendliness 94/100
-
Create parent directories only after the containment check in InstallHelper.TryExtractToDirectory Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PowerShell/PSResourceGet#2056 ·