Skip to content

Heap buffer overflow in version 2.8.0.0 with abstract Linux sockets #382

Description

@remyoudompheng

Hello,

There is a heap overflow in pokeSockAddr that was fixed in release 3.0.0.0 when using Linux abstract Unix sockets. As far as I know it is present in at least all versions from 2.6.3.3 to 2.8.0.0.

The following program reproduces a segfault with ghc 8.6.3 when compiled with the threaded runtime

import Network.Socket
import Control.Monad (forM)

main :: IO ()
main = do
    forM [1..100] $ \n -> do
        putStrLn (show n ++ " characters")
        sock <- socket AF_UNIX Stream defaultProtocol
        bind sock (SockAddrUnix ("\0" ++ (replicate n 't')))
        close sock
    return ()

with the following output:

$ ghc -threaded -dynamic -package network test.hs
$ ./test
...
86 characters
zsh: segmentation fault (core dumped)  ./test

Since many systems are still using network 2.8.0.0 (like the Stackage distribution) I would like to know whether a 2.8.0.1 version could be released.

The fix would be to have pokeSockAddr _ sa@(SockAddrUnix _) always use

zeroMemory p $ fromIntegral $ sizeOfSockAddr sa

like it does in the 3.x version.

Activity

  1. eborden commented on Feb 19, 2019

    @eborden
    Collaborator

    @remyoudompheng I would gladly accept a PR for 2.8.0.1.

  2. remyoudompheng commented on Feb 19, 2019

    @remyoudompheng
    Author

    For completeness I included in the PR a variant of commit c8042c7 to check lengths of ordinary Unix socket addresses.

    You can obtain consistent crashes with a program like

    import Network.Socket
    import Control.Monad (forM)
    import Control.Exception
    import System.Directory
    
    main :: IO ()
    main = do
        forM [200..1000] $ \n -> do
            putStrLn (show n ++ " characters")
            sock <- socket AF_UNIX Stream defaultProtocol
            do {
                bind sock (SockAddrUnix (replicate n 't' :: String));
                removeFile (replicate n 't' :: FilePath);
            } `catch` (print :: SomeException -> IO ())
            close sock
        return ()
    

    In this case it is probably easier to obtain more arbitrary memory writes.

  3. kazu-yamamoto commented on Apr 24, 2019

    @kazu-yamamoto
    Collaborator

    #400 fixes this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions