libubox/tests
Alban Bedel 89fb6136ad libubox: runqueue: fix use-after-free bug
Fixes a use-after-free bug in runqueue_task_kill():

 Invalid read of size 8
    at runqueue_task_kill (runqueue.c:200)
    by uloop_process_timeouts (uloop.c:505)
    by uloop_run_timeout (uloop.c:542)
    by uloop_run (uloop.h:111)
    by main (tests/test-runqueue.c:126)
  Address 0x5a4b058 is 24 bytes inside a block of size 208 free'd
    at free
    by runqueue_task_complete (runqueue.c:234)
    by runqueue_task_kill (runqueue.c:199)
    by uloop_process_timeouts (uloop.c:505)
    by uloop_run_timeout (uloop.c:542)
    by uloop_run (uloop.h:111)
    by main (tests/test-runqueue.c:126)
  Block was alloc'd at
    at calloc
    by add_sleeper (tests/test-runqueue.c:101)
    by main (tests/test-runqueue.c:123)

Since commit 11e8afea (runqueue should call the complete handler from
more places) the call to the complete() callback has been moved to
runqueue_task_complete().  However in runqueue_task_kill()
runqueue_task_complete() is called before the kill() callback.  This
will result in a use after free if the complete() callback frees the
task struct.

Furthermore runqueue_start_next() is already called at the end of
runqueue_task_complete(), so there is no need to call it again in
runqueue_task_kill().

The issue was that the _complete() callback frees the memory used by the
task struct, which is then read after the _complete() callback returns.

Ref: FS#3016
Signed-off-by: Alban Bedel <albeu@free.fr>
[initial test case, kill cb comment fix]
Signed-off-by: Chris Nisbet <nischris@gmail.com>
[testcase improvements and commit subject/description tweaks]
Signed-off-by: Petr Štetiar <ynezz@true.cz>
2020-05-21 15:58:46 +02:00
..
cram libubox: runqueue: fix use-after-free bug 2020-05-21 15:58:46 +02:00
fuzz blobmsg: blobmsg_parse and blobmsg_parse_array oob read fixes 2020-01-20 16:54:10 +01:00
shunit2 tests: include json script shunit2 based testing 2020-01-12 19:17:17 +01:00
CMakeLists.txt tests: include json script shunit2 based testing 2020-01-12 19:17:17 +01:00
test-avl.c add cram based unit tests 2019-11-24 13:26:58 +01:00
test-b64.c tests: prefer dynamically allocated buffers 2020-01-20 16:54:10 +01:00
test-b64_decode.c base64: fix possible null pointer dereference 2019-11-24 13:26:58 +01:00
test-b64_encode.c base64: fix possible null pointer dereference 2019-11-24 13:26:58 +01:00
test-blob-parse.c tests: prefer dynamically allocated buffers 2020-01-20 16:54:10 +01:00
test-blobmsg-parse.c tests: prefer dynamically allocated buffers 2020-01-20 16:54:10 +01:00
test-blobmsg-procd-instance.c tests: prefer dynamically allocated buffers 2020-01-20 16:54:10 +01:00
test-blobmsg.c blobmsg_json: prefer snprintf usage 2020-01-20 16:54:10 +01:00
test-blobmsg_check_array.c tests: blobmsg: add test case 2020-02-27 21:56:20 +01:00
test-json-script.c add cram based unit tests 2019-11-24 13:26:58 +01:00
test-list.c tests: list: add test case for list_empty iterator 2020-05-21 13:43:00 +02:00
test-runqueue.c libubox: runqueue: fix use-after-free bug 2020-05-21 15:58:46 +02:00