Closed
Bug 1023121
(CVE-2014-1555)
Opened 11 years ago
Closed 11 years ago
Use-after-free in nsDocLoader::OnProgress
Categories
(Core :: DOM: Navigation, defect)
Tracking
()
People
(Reporter: persona, Assigned: bzbarsky)
Details
(4 keywords, Whiteboard: [qa-][adv-main31+][adv-esr24.7+] original description in comment 26)
Attachments
(2 files)
11 years ago
649 bytes,
patch
|
Details | Diff | Splinter Review | |
2.90 KB,
patch
|
smaug
:
review+
Sylvestre
:
approval-mozilla-aurora+
Sylvestre
:
approval-mozilla-beta+
Sylvestre
:
approval-mozilla-esr24+
abillings
:
sec-approval+
|
Details | Diff | Splinter Review |
Oh I forgot to mention the actual memory write (corruption) happens on line 1087. All lines numbers are from FIREFOX_AURORA_29_BASE: https://hg.mozilla.org/mozilla-central/file/ba2cc1eda988/uriloader/base/nsDocLoader.cpp
Updated•11 years ago
|
Keywords: csectype-uaf,
valgrind
Comment 2•11 years ago
|
||
bz and smaug: could one of you look into this? Thanks. This code does look pretty sketchy.
Flags: needinfo?(bzbarsky)
![]() |
Assignee | |
Comment 4•11 years ago
|
||
Yeah, this is bogus. FireOnStateChange can run random script from extensions which can start new loads, which will in fact modify this hashtable. Jethro, nice catch.
Flags: needinfo?(bugs)
Updated•11 years ago
|
Comment 5•11 years ago
|
||
It looks like this affects every branch.
status-firefox30:
--- → affected
status-firefox31:
--- → affected
status-firefox32:
--- → affected
status-firefox33:
--- → affected
status-firefox-esr24:
--- → affected
OS: Linux → All
Hardware: x86_64 → All
![]() |
Assignee | |
Comment 6•11 years ago
|
||
Attachment #8437725 -
Flags: review?(bugs)
![]() |
Assignee | |
Updated•11 years ago
|
Assignee: nobody → bzbarsky
Status: NEW → ASSIGNED
Comment 7•11 years ago
|
||
Comment on attachment 8437725 [details] [diff] [review]
Update our progress in docloader before calling state change listeners
Looks like other cases are ok.
(OnStatus, OnStopRequest etc.)
Attachment #8437725 -
Flags: review?(bugs) → review+
![]() |
Assignee | |
Comment 8•11 years ago
|
||
Comment on attachment 8437725 [details] [diff] [review]
Update our progress in docloader before calling state change listeners
[Security approval request comment]
How easily could an exploit be constructed based on the patch? Probably not very easily, especially in a stock Firefox.
Do comments in the patch, the check-in comment, or tests included in the patch paint a bulls-eye on the security problem? Somewhat, yes. I could remove the comment, but then this is likely to get re-broken again in the future...
Which older supported branches are affected by this flaw? All of them, I think.
If not all supported branches, which bug introduced the flaw?
Do you have backports for the affected branches? If not, how different, hard to create, and risky will they be? I think this should be easy to backport.
How likely is this patch to cause regressions; how much testing does it need? I _think_ this should be pretty safe, but you can never be sure with this code.
Attachment #8437725 -
Flags: sec-approval?
Updated•11 years ago
|
Comment 9•11 years ago
|
||
Comment on attachment 8437725 [details] [diff] [review]
Update our progress in docloader before calling state change listeners
Sec-approval+ for checkin on 6/24 or later.
Attachment #8437725 -
Flags: sec-approval? → sec-approval+
![]() |
Assignee | |
Comment 10•11 years ago
|
||
OK. Should I be requesting branch approvals after that point, then?
Flags: needinfo?(abillings)
Comment 11•11 years ago
|
||
(In reply to Boris Zbarsky [:bz] from comment #10)
> OK. Should I be requesting branch approvals after that point, then?
Yes, that would be a good idea. I think we should take this everywhere.
Flags: needinfo?(abillings)
![]() |
Assignee | |
Comment 12•11 years ago
|
||
We should take this everywhere, yes. My real question was whether I effectively need to wait until the 24th to request branch approvals.
Flags: needinfo?(abillings)
Comment 13•11 years ago
|
||
Oh, I don't care though you need to check into trunk and have it go green before checking into branch.
Flags: needinfo?(abillings)
![]() |
Assignee | |
Comment 14•11 years ago
|
||
Comment on attachment 8437725 [details] [diff] [review]
Update our progress in docloader before calling state change listeners
[Approval Request Comment]
Bug caused by (feature/regressing bug #): Been around forever.
User impact if declined: Possibly-exploitable crashes.
Testing completed (on m-c, etc.):
Risk to taking this patch (and alternatives if risky): Medium risk, I think. A
possibly less risky alternative would be to reget the hashtable entry instead
of reordering the write, but I worry a (small) bit about performance impact.
And even the regetting would need to be done pretty carefully, so might not be
any less risky.
String or IDL/UUID changes made by this patch: None.
Attachment #8437725 -
Flags: approval-mozilla-release?
Attachment #8437725 -
Flags: approval-mozilla-esr24?
Attachment #8437725 -
Flags: approval-mozilla-beta?
Attachment #8437725 -
Flags: approval-mozilla-b2g30?
Attachment #8437725 -
Flags: approval-mozilla-b2g28?
Attachment #8437725 -
Flags: approval-mozilla-b2g26?
Attachment #8437725 -
Flags: approval-mozilla-b2g18?
Attachment #8437725 -
Flags: approval-mozilla-aurora?
Reporter | ||
Comment 15•11 years ago
|
||
Comment on attachment 8437725 [details] [diff] [review]
Update our progress in docloader before calling state change listeners
I'm now running 30.0+build1-0ubuntu0.13.10.3 with this applied, will update if I notice any problems.
![]() |
Assignee | |
Updated•11 years ago
|
Flags: sec-bounty?
Updated•11 years ago
|
tracking-firefox31:
--- → +
tracking-firefox32:
--- → +
Comment 16•11 years ago
|
||
Comment on attachment 8437725 [details] [diff] [review]
Update our progress in docloader before calling state change listeners
This is not a chemspill driver, and will be landing in a couple weeks to prepare for FF31 release, so removing the approval-mozilla-release flag.
Attachment #8437725 -
Flags: approval-mozilla-release?
![]() |
Assignee | |
Comment 17•11 years ago
|
||
Flags: in-testsuite?
Target Milestone: --- → mozilla33
Updated•11 years ago
|
Whiteboard: [checkin on 6/24]
Comment 18•11 years ago
|
||
Status: ASSIGNED → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Updated•11 years ago
|
Attachment #8437725 -
Flags: approval-mozilla-esr24?
Attachment #8437725 -
Flags: approval-mozilla-esr24+
Attachment #8437725 -
Flags: approval-mozilla-beta?
Attachment #8437725 -
Flags: approval-mozilla-beta+
Attachment #8437725 -
Flags: approval-mozilla-aurora?
Attachment #8437725 -
Flags: approval-mozilla-aurora+
Updated•11 years ago
|
Attachment #8437725 -
Flags: approval-mozilla-b2g30?
Attachment #8437725 -
Flags: approval-mozilla-b2g28?
Attachment #8437725 -
Flags: approval-mozilla-b2g26?
Attachment #8437725 -
Flags: approval-mozilla-b2g18?
Comment 19•11 years ago
|
||
https://hg.mozilla.org/releases/mozilla-aurora/rev/bf28f13cb7ac
https://hg.mozilla.org/releases/mozilla-beta/rev/c12e143ed44f
https://hg.mozilla.org/releases/mozilla-b2g30_v1_4/rev/ad0c7fed3273
https://hg.mozilla.org/releases/mozilla-b2g28_v1_3/rev/ad92a3777ede
https://hg.mozilla.org/releases/mozilla-esr24/rev/43b51a61e060
status-b2g-v1.3:
--- → fixed
status-b2g-v1.3T:
--- → affected
status-b2g-v1.4:
--- → fixed
status-b2g-v2.0:
--- → fixed
status-b2g-v2.1:
--- → fixed
Updated•11 years ago
|
Updated•11 years ago
|
Flags: sec-bounty? → sec-bounty+
Comment 21•11 years ago
|
||
jethro asked that breakpad links remain private when this bug is opened up.
Comment 22•11 years ago
|
||
for hall of fame credit should be listed as
Jethro Beekman, Security Researcher at University of California, Berkeley
Comment 23•11 years ago
|
||
If someone provides a URL, test or other STR, I'm happy to verify, but in the absence of that, I'm marking [qa-] for verification purposes.
Whiteboard: [qa-]
Updated•11 years ago
|
Whiteboard: [qa-] → [qa-][adv-main31+][adv-esr24.7+]
Updated•11 years ago
|
Alias: CVE-2014-1555
Comment 24•11 years ago
|
||
(In reply to chris hofmann from comment #21)
> jethro asked that breakpad links remain private when this bug is opened up.
Why? That means the bug description itself remains invisible.
Comment 21 is private:
false
Reporter | ||
Comment 25•11 years ago
|
||
I don't want the breakpad links to be publicly associated with me. If you can edit out the links from the comment, it's fine if the rest is made public.
Comment 26•11 years ago
|
||
-----Jethro's comment 0 minus links-------
Since Firefox 29 (29.0+build1-0ubuntu0.13.10.3 on Linux x86_64 3.11.4-vhost-blk+), I have been experiencing random SEGFAULTs during normal browser use. At first I was unable to discern a pattern, so I suspected memory corruption 'somewhere'. I finally found a website that on load would semi-reliably (>50% of the time) crash the browser. Using valgrind, I was able to find the source:
==27741== Invalid read of size 8
==27741== at 0x84DA95A: nsDocLoader::OnProgress(nsIRequest*, nsISupports*, unsigned long, unsigned long) (nsDocLoader.cpp:1084)
...
==27741== Address 0x3dda9110 is 1,168 bytes inside a block of size 6,144 free'd
==27741== at 0x4C2B60C: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==27741== by 0x8127265: ChangeTable(PLDHashTable*, int) (pldhash.cpp:483)
==27741== by 0x81276A1: PL_DHashTableOperate (pldhash.cpp:580)
==27741== by 0x84DAFC1: nsDocLoader::OnStopRequest(nsIRequest*, nsISupports*, tag_nsresult) (nsDocLoader.cpp:632)
What happens is:
1. On line nsDocLoader.cpp:1033, the nsRequestInfo* info is retrieved.
2. On line 1080 FireOnStateChange might be called. This can result in all kinds of things happening in the mean time, I've seen call stacks with FireOnStateChange 80 call frames deep. Some other request that was handled might cause the mRequestInfoHash table to be re-hashed, freeing the nsRequestInfo that info was pointing to. OCSP requests in particular seem to be affected, perhaps because it adds to the call stack in ways other requests don't.
3. On line 1084, info gets used anyway (use-after-free). The freed memory might have been reallocated in the mean-time, resulting in 8 "random" bytes being overwritten. This is sometimes harmless, sometimes it causes a SEGFAULT. I have seen cases of up to 10 different use-after-frees happening before the crash.
The attached patch will highlight the problem, and seemingly fix it if you uncomment the commented line. I suggest an actual fix be written by someone who knows the codebase.
Filing as a security bug because local process memory can be overwritten with network-controlled data (e.g. number of bytes received). A skillful attacker might be able to craft a website that does the just right set of requests, responding with the just right responses to trigger this bug (perhaps multiple times) and overwrite memory with its chosen data.
The following breakpad reports are all the reports from my installation since the upgrade to Firefox 29, and might be related. It's hard to tell if any of these are caused by this, because the nature of the bug is such that a crash will happen much later than the memory corruption, so there might be no trace of the causing function. Also, I looked through Mercurial and could not figure out what changed that caused this to suddenly started happening in Firefox 29.
Whiteboard: [qa-][adv-main31+][adv-esr24.7+] → [qa-][adv-main31+][adv-esr24.7+] original description in comment 26
Updated•9 years ago
|
Group: core-security → core-security-release
Updated•9 years ago
|
Group: core-security-release
Updated•9 months ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Comment 1
•