Repository navigation
Potential buffer-overflow from string operations in function array_from_pyobj of fortranobject.c #19000
Description
Activity
Anyone can help confirm this issue? thanks.
This report is almost certainly valid, but I suspect there are lower-hanging bugs in the f2py code. It's probably easier to assemble the strings on the heap using the Python C API than mess with keeping track of buffer lengths.
Thanks @Daybreak2019 - string support in f2py is undergoing some changes, I'll include this in the things to check.
Hi, any update on this issue? It was recently assigned CVE-2021-41496.
- added a commit that references this issue
on Dec 20, 2021 I don't think the CVE text is quite correct. I do not see the "by carefully constructing an array with negative values" working (I guess "array" refers to the C array of
dims), these are negative dimensions though and such an array should never exist, there would be far worse problems.I would have to check closer, but I think that negative values are always placed there by f2py/the wrapping module itself. Users may be able to trigger the error (not quite sure how), but I do not think they can craft it or the message based on malicious data (the one exception is that there is a test function calling this more directly, but this is also not available by passing malicious data).
To be clear, this should be fixed and should be easy enough (contributions also welcome!). @melissawm, @HaoZeke do you have a bit of time to just check this off? I still doubt there is much of an attack vector at all, unless you are wrapping very high dimensional working arrays and additional expose an API that allows "malicious data" to toggle whether or not the path is taken.
Reacted by Carlos López and Rohit GoswamiAh, that was quick, cool :). Not related to this, but we may want to replace all other
sprintf's here withPyErr_Formator similar, since the f2py-cleanup drive is continuing.- added 3 commits that reference this issue
on Dec 20, 2021 2 remaining items
- added a commit that references this issue
on Apr 19, 2022
Reproducing code example:
Snippet:
Error message:
File: numpy/f2py/src/fortranobject.c
Function: array_from_pyobj (line 724 : 733)
Optional call-path: External -> fortran_setattr -> array_from_pyobj
Details in description
When we run our analysis tool on NumPy, a few Inappropriate string operations are reported at call sites of function strcpy, sprintf, and strcat in array_from_pyobj. There are no boundary checks at these points despite "mess" seems large enough to ensure the operations safe except for the point shown above.
As a suggestion, it is better to replace these functions with strncpy, strncat, and snprintf.
NumPy/Python version information:
the main branch of NumPy