Closed Bug 2074390 Opened 13 days ago Closed 11 days ago

IndexedDB: using resizable ArrayBuffer as a key crashes the content process

Categories

(Core :: Storage: IndexedDB, defect)

defect

Tracking

()

RESOLVED FIXED
158 Branch
Tracking Status
firefox158 --- fixed

People

(Reporter: abienner, Assigned: abienner)

Details

(Whiteboard: [nosec][deduped])

Attachments

(2 files)

Using resizable ArrayBuffer (i.e. defined with maxByteLength argument) as keys results in a crash because of a MOZ_RELEASE_ASSERT, triggered from here.
key = new ArrayBuffer(8, { maxByteLength: 16 });
Same for views:
key = new Uint8Array(new ArrayBuffer(8, { maxByteLength: 16 }));

See attached example.

Loading it in Firefox results in a tab crash, with both a plain array buffer and a view (triggered when passing ?variant=view URL parameter).

On Safari, it works.
On Chrome, it throws a TypeError.

I don't see anything in the spec that forbids it, so we should either support it eventually, or raise a spec issue.

As a first step, since it doesn't work for us, and doesn't work on Chrome either, it's probably OK to just throw an error.

While this is a crash, I'm not sure this is really a security bug, since it crashes on assert, but in doubt, I preferred to mark it as such.

Assignee: nobody → abienner
Status: NEW → ASSIGNED
Group: core-security → dom-core-security

:abienner, please review the release status flags for beta, release, and ESR and update each one as appropriate.

For each version, indicate whether it is affected, unaffected, disabled, or wontfix if it is affected but does not need to be fixed on that branch.

Flags: needinfo?(abienner)

This rating has been determined by our automated bug rating tool (currently under development). No validation or verification has been performed.

Rating: nosec

Explanation: Not a security bug. Verified in source: a resizable ArrayBuffer (or a view onto one) used as an IndexedDB key reaches Key::EncodeBinary -> ProcessArrayBufferOrView -> ArrayBuffer/ArrayBufferView::ProcessData -> GetCurrentData(), which hits MOZ_RELEASE_ASSERT(!isResizable()) in TypedArray.h:681-683 because the bindings never reject resizable buffers. Impact: the assert fires before getData() is ever called, so the buffer memory is never accessed unsafely; this is a deterministic, controlled abort with no memory corruption. Attack vector: web content calling IDBObjectStore.put() with a resizable ArrayBuffer/view as the key. Reachability: confirmed, runs in the content process and crashes only that tab. A safe crash of a single content process is not a security issue.

Whiteboard: [nosec]

This is a release assert, so I think it is okay to unhide.

Group: dom-core-security

Automatic triage (under development): deduplication, sec-rating

This duplicate check has been performed by our automated bug triage tool (currently under development). No validation or verification has been performed.

Bugs considered:

  • bug 1806532 — similar symptoms but a different root cause
  • bug 2069588 — similar symptoms but a different root cause
  • bug 2019806 — similar symptoms but a different root cause

This rating has been determined by our automated bug rating tool (currently under development). No validation or verification has been performed.

Whiteboard: [nosec] → [nosec][deduped]
Attachment #9646803 - Attachment description: (secure) → Bug 2074390 - IndexedDB: reject resizable array buffers (or view on such buffers) used as keys. r?#dom-storage

I've opened a spec issue to follow up on this.

Flags: needinfo?(abienner)
Pushed by abienner@mozilla.com: https://github.com/mozilla-firefox/firefox/commit/a23a6b00555d https://hg.mozilla.org/integration/autoland/rev/d94056a9cb9c IndexedDB: reject resizable array buffers (or view on such buffers) used as keys. r=dom-storage-reviewers,asuth
Status: ASSIGNED → RESOLVED
Closed: 11 days ago
Resolution: --- → FIXED
Target Milestone: --- → 158 Branch
QA Whiteboard: [qa-triage-done-c159/b158]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: