Bug 693704 - yajl may infloop; it will also dereference NULL on OOM
Summary: yajl may infloop; it will also dereference NULL on OOM
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: yajl
Version: 6.3
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Daniel Berrangé
QA Contact: BaseOS QE - Apps
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-04-05 11:36 UTC by Jim Meyering
Modified: 2016-08-26 12:43 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-08-26 12:43:27 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Jim Meyering 2011-04-05 11:36:00 UTC
Description of problem: when appending requires a buffer of size 2^31+1 or larger, yajl gets stuck in an infloop

It also will dereference NULL in numerous places upon failed malloc and realloc.
Reported upstream:
http://librelist.com/browser//yajl/2011/4/5/avoid-infloop-upon-buffer-append/
http://librelist.com/browser//yajl/2011/4/5/patch-add-assertions-to-avoid-dereferencing-null-upon-oom/

Version-Release number of selected component (if applicable):


How reproducible: NA
found via inspection, though I can write code to provoke the infloop

Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:

Comment 2 RHEL Program Management 2011-04-05 11:43:35 UTC
Since RHEL 6.1 External Beta has begun, and this bug remains
unresolved, it has been rejected as it is not proposed as
exception or blocker.

Red Hat invites you to ask your support representative to
propose this request, if appropriate and relevant, in the
next release of Red Hat Enterprise Linux.

Comment 4 Daniel Berrangé 2016-08-26 12:43:27 UTC
Fixing this would effectively require rebasing yajl to the new upstream version which fixes the code to use size_t and do propr OOM chcking. This new version however is not ABI compatible, so not something that can be done in a RHEL update


Note You need to log in before you can comment on or make changes to this bug.