Fix SIGSEGV on malformed Text field
C++ helper c_reraise_kj_exception() (capnp/helpers/capabilityHelper.cpp) unconditionally dereferences the PyObject* returned by wrap_kj_exception_for_reraise() (capnp/lib/capnp.pyx). For a specific class of malformed input -- a Cap'n Proto Text field whose NUL terminator is corrupt -- the wrapper returns NULL, and the subsequent "obj->ob_type" access dereferences NULL (offset 0x8) inside the C extension, producing a deterministic, UNCATCHABLE SIGSEGV. libcapnp itself detects the corruption correctly and would raise a catchable KjException for the sibling code path; only this reraise helper crashes. The malformed bytes reach the crash through the documented public API Type.from_bytes(...) + lazy field access -- exactly how pycapnp consumers deserialize untrusted Cap'n Proto messages received over the network / RPC / from files. A single flipped byte in an attacker-controlled message takes down the consuming process; the crash cannot be caught with try/except, so no graceful degradation is possible.
This commit is contained in:
@@ -16,6 +16,9 @@ void c_reraise_kj_exception() {
|
||||
}
|
||||
catch (kj::Exception& exn) {
|
||||
auto obj = wrap_kj_exception_for_reraise(exn);
|
||||
if (obj == nullptr) {
|
||||
return;
|
||||
}
|
||||
PyErr_SetObject((PyObject*)obj->ob_type, obj);
|
||||
Py_DECREF(obj);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user