Skip to content

DataContractJsonSerializer.ReadObject throws IndexOutOfRangeException #1410

Description

@Metalnem

DataContractJsonSerializer.ReadObject sometimes throws IndexOutOfRangeException. Here's the full program that reproduces this:

using System.IO;
using System.Runtime.Serialization;
using System.Runtime.Serialization.Json;
using System.Text;

namespace CoreFX.Fuzz
{
  public class Program
  {
    public static void Main(string[] args)
    {
      var json = @"{""a"":N2,]}";
      var bytes = Encoding.UTF8.GetBytes(json);
      var stream = new MemoryStream(bytes);
      var serializer = new DataContractJsonSerializer(typeof(object));

      serializer.ReadObject(stream);
    }
  }
}

The stack trace:

Exception has occurred: CLR/System.IndexOutOfRangeException
An unhandled exception of type 'System.IndexOutOfRangeException' occurred in System.Private.DataContractSerialization.dll: 'Index was outside the bounds of the array.'
   at System.Runtime.Serialization.Json.XmlJsonReader.ExitJsonScope()
   at System.Runtime.Serialization.Json.XmlJsonReader.Read()
   at System.Xml.XmlBaseReader.ReadEndElement()
   at System.Runtime.Serialization.Json.JsonClassDataContract.ReadJsonValueCore(XmlReaderDelegator jsonReader, XmlObjectSerializerReadContextComplexJson context)
   at System.Runtime.Serialization.Json.JsonDataContract.ReadJsonValue(XmlReaderDelegator jsonReader, XmlObjectSerializerReadContextComplexJson context)
   at System.Runtime.Serialization.Json.XmlObjectSerializerReadContextComplexJson.ReadDataContractValue(DataContract dataContract, XmlReaderDelegator reader)
   at System.Runtime.Serialization.XmlObjectSerializerReadContext.InternalDeserialize(XmlReaderDelegator reader, String name, String ns, DataContract& dataContract)
   at System.Runtime.Serialization.XmlObjectSerializerReadContextComplex.InternalDeserialize(XmlReaderDelegator xmlReader, Type declaredType, DataContract dataContract, String name, String ns)
   at System.Runtime.Serialization.Json.DataContractJsonSerializerImpl.InternalReadObject(XmlReaderDelegator xmlReader, Boolean verifyObjectName)
   at System.Runtime.Serialization.XmlObjectSerializer.InternalReadObject(XmlReaderDelegator reader, Boolean verifyObjectName, DataContractResolver dataContractResolver)
   at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName, DataContractResolver dataContractResolver)
   at System.Runtime.Serialization.Json.DataContractJsonSerializerImpl.ReadObject(XmlDictionaryReader reader)
   at System.Runtime.Serialization.Json.DataContractJsonSerializerImpl.ReadObject(Stream stream)
   at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(Stream stream)

The environment:

.NET Core SDK (reflecting any global.json):
 Version:   2.2.103
 Commit:    8edbc2570a

Runtime Environment:
 OS Name:     Mac OS X
 OS Version:  10.14
 OS Platform: Darwin
 RID:         osx.10.14-x64
 Base Path:   /usr/local/share/dotnet/sdk/2.2.103/

Found via SharpFuzz.

Activity

  1. Lxiamail commented on Apr 3, 2019

    @Lxiamail
    Contributor

    We should throw a different exception other than IndexOutOfRangeException. However, due to the issue is not reported by real world scenario, this is lower priority issue.

  2. added this to the Future milestone on Jan 7, 2020
  3. added and removed
    untriagedNew issue has not been triaged by the area owner
    on Jan 7, 2020
  4. StephenBonikowsky commented on Feb 28, 2020

    @StephenBonikowsky
    Contributor

    @imcarolwang Another issue that your team can look into fixing.

  5. removed this from the Future milestone on Mar 5, 2020
  6. added this to the Future milestone on Jul 1, 2020
  7. imcarolwang commented on Jul 3, 2020

    @imcarolwang
    Contributor

    The program throws the same IndexOutOfRangeException when running on .NetFramework project.

  8. HongGit commented on Oct 8, 2020

    @HongGit
    Contributor

    @Metalnem this does not seem to be a regression from .NET Framework. If you still need us to investigate further, please provide a repro app.

  9. ghost locked as resolved and limited conversation to collaborators on Dec 14, 2020
  10. danmoseley commented on Oct 9, 2021

    @danmoseley
    Contributor

    it's OK to not fix this, but just noting that the repro app is the code above. I just ran it against 6.0 and it produced this result.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions