Closed Bug 2014865 (CVE-2026-4724) Opened 7 months ago Closed 7 months ago

Assertion failure: mStart <= mEnd (Invalid Interval), at /builds/worker/workspace/obj-build/dist/include/Intervals.h:48

Categories

(Core :: Audio/Video, defect, P2)

x86_64
Linux
defect

Tracking

()

VERIFIED FIXED
149 Branch
Tracking Status
firefox-esr115 --- wontfix
firefox-esr140 --- wontfix
firefox147 --- wontfix
firefox148 --- wontfix
firefox149 --- fixed

People

(Reporter: jkratzer, Assigned: padenot)

Details

(5 keywords, Whiteboard: [bugmon:bisected,confirmed][adv-main149+])

Attachments

(3 files)

Reproduced on mozilla-central rev 57fbf639ea5b (built with: --enable-debug --enable-fuzzing).

Testcase can be reproduced using the following commands:

$ pip install fuzzfetch grizzly-framework pipx --upgrade
$ python -m pipx ensurepath
$ fuzzfetch --build 57fbf639ea5b --debug --fuzzing  -n firefox
$ grizzly-replay-bugzilla ./firefox/firefox <bugid>
Assertion failure: mStart <= mEnd (Invalid Interval), at /builds/worker/workspace/obj-build/dist/include/Intervals.h:48

    ==2879099==ERROR: UndefinedBehaviorSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7df8ec852e82 bp 0x7ffd894e5930 sp 0x7ffd894e58a0 T2879099)
    ==2879099==The signal is caused by a WRITE memory access.
    ==2879099==Hint: address points to the zero page.
        #0 0x7df8ec852e82 in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:237:3
        #1 0x7df8ec852e82 in Interval<mozilla::media::TimeUnit &, mozilla::media::TimeUnit &> /builds/worker/workspace/obj-build/dist/include/Intervals.h:48:5
        #2 0x7df8ec852e82 in mozilla::TrackBuffersManager::RangeRemoval(mozilla::media::TimeUnit, mozilla::media::TimeUnit) /dom/media/mediasource/TrackBuffersManager.cpp:330:22
        #3 0x7df8ec852253 in mozilla::dom::SourceBuffer::RangeRemoval(double, double) /dom/media/mediasource/SourceBuffer.cpp:353:9
        #4 0x7df8ec851edb in mozilla::dom::SourceBuffer::Remove(double, double, mozilla::ErrorResult&) /dom/media/mediasource/SourceBuffer.cpp:282:3
        #5 0x7df8ead64392 in mozilla::dom::SourceBuffer_Binding::remove(JSContext*, JS::Handle<JSObject*>, void*, JSJitMethodCallArgs const&) /builds/worker/workspace/obj-build/dom/bindings/./SourceBufferBinding.cpp:1012:24
        #6 0x7df8eb657df6 in bool mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ThrowExceptions>(JSContext*, unsigned int, JS::Value*) /dom/bindings/BindingUtils.cpp:3309:13
        #7 0x7df8f0223574 in CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&) /js/src/vm/Interpreter.cpp:490:13
        #8 0x7df8f0222e1f in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) /js/src/vm/Interpreter.cpp:586:12
        #9 0x7df8ef82cb83 in js::jit::DoCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, unsigned int, JS::Value*, JS::MutableHandle<JS::Value>) /js/src/jit/BaselineIC.cpp:1698:10
        #10 0x2e520e81adee  ([anon:js-executable-memory]+0xbdee)
    
    ==2879099==Register values:
    rax = 0x0000000000000000  rbx = 0x00005fb755f27738  rcx = 0x0000000000000030  rdx = 0x00007df8f9a04563
    rdi = 0x00007df8f9a05700  rsi = 0x0000000000000000  rbp = 0x00007ffd894e5930  rsp = 0x00007ffd894e58a0
     r8 = 0x0000000000000000   r9 = 0x0000000000000003  r10 = 0x0000000000000002  r11 = 0x0000000000000293
    r12 = 0x00007ffd894e5958  r13 = 0x00007ffd894e58c8  r14 = 0x00005fb755f26e60  r15 = 0x00005fb756075fc0
    UndefinedBehaviorSanitizer can not provide additional info.
    SUMMARY: UndefinedBehaviorSanitizer: SEGV (/home/jkratzer/builds/m-c-20260205090734-fuzzing-debug/libxul.so+0x9052e82) (BuildId: c143802c55c45c489dd220fc3aaf3f64e16a58ac)
    ==2879099==ABORTING
Attached file Testcase —
Group: dom-core-security → media-core-security

Verified bug as reproducible on mozilla-central 20260205213633-279b57ef4bf0.
Unable to bisect testcase (Testcase reproduces on start build!):

Start: ce0f77cae5a91e2cb4b1ec859117e08aa1182c52 (20250207164009)
End: 57fbf639ea5bd2e56dd9e1bef16497372385229d (20260205090734)
BuildFlags: BuildFlags(asan=False, tsan=False, debug=True, fuzzing=True, coverage=False, valgrind=False, no_opt=False, fuzzilli=False, nyx=False, searchfox=False, afl=False)

Whiteboard: [bugmon:confirm] → [bugmon:bisected,confirmed]
Blocks: media-triage
Attached file (secure) —

TimeUnit::FromSeconds() had undefined behavior when converting values at the
boundary of int64_t representability. Specifically, when the input value times
the base equals exactly 2^63:

  1. static_cast<double>(INT64_MAX) rounds UP to 2^63 (INT64_MAX = 2^63-1 cannot
    be exactly represented as double)
  2. The check used strict >, so inBase == 2^63 passed the overflow check
  3. static_cast<int64_t>(std::round(2^63)) is undefined behavior since 2^63
    exceeds INT64_MAX, producing INT64_MIN on x86-64
  4. This created invalid TimeUnits, causing assertion failures in TimeInterval
    construction (mStart <= mEnd)

The fix changes > to >= to properly catch this boundary case.

Assignee: nobody → padenot
Status: NEW → ASSIGNED

I guess I'll mark it sec-moderate because of the undefined behavior, but it doesn't sound particularly exploitable.

Severity: -- → S2
Priority: -- → P2
Pushed by padenot@mozilla.com: https://github.com/mozilla-firefox/firefox/commit/79bfbc088d67 https://hg.mozilla.org/integration/autoland/rev/0cc7e9e502bd Fix int64_t overflow in TimeUnit::FromSeconds boundary condition. r=media-playback-reviewers,alwu
Group: media-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Flags: in-testsuite+
Resolution: --- → FIXED
Target Milestone: --- → 149 Branch

Verified bug as fixed on rev mozilla-central 20260213044212-cabf73b570b5.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Status: RESOLVED → VERIFIED
Keywords: bugmon
No longer blocks: media-triage
Whiteboard: [bugmon:bisected,confirmed] → [bugmon:bisected,confirmed][adv-main149+]
Alias: CVE-2026-4724
Group: core-security-release
Keywords: keep-hidden
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: