gnome-software (5) g_realloc → g_array_maybe_expand → g_array_set_size → g_byte_array_set_size → read_cb

Bug #1740865 reported by errors.ubuntu.com bug bridge
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
snapd-glib (Ubuntu)
Fix Released
High
Robert Ancell
Bionic
Fix Released
High
Robert Ancell
Cosmic
Fix Released
High
Robert Ancell

Bug Description

[Impact]
snapd-glib can do an invalid memory access when parsing HTTP chunked data. Found doing code inspection and testing based on crash reports.

[Test Case]
No specific trigger - just look for reduced reports on errors.ubuntu.com.

[Regression Potential]
Some risk of further breaking HTTP handling in snapd-glib. Updated algorithm tested in a test program run through valgrind to give confidence in the changes.

Error reports:

https://errors.ubuntu.com/problem/d94c431d27115bab216f9e1ea756f876e7cd933b

summary: - /usr/bin/gnome-
- software:5:g_realloc:g_array_maybe_expand:g_array_set_size:g_byte_array_set_size:read_cb
+ gnome-software (5) g_realloc → g_array_maybe_expand → g_array_set_size →
+ g_byte_array_set_size → read_cb
Changed in gnome-software (Ubuntu):
importance: Undecided → Medium
status: New → Confirmed
Revision history for this message
Robert Ancell (robert-ancell) wrote :

The crash report shows snapd-glib trying to allocate 2.6G of memory...

Revision history for this message
Robert Ancell (robert-ancell) wrote :

It looks like the cause is the HTTP chunk handling. Testing of this code showed a couple of buffer overruns, which are now fixed in snapd-glib 1.40.

Changed in gnome-software (Ubuntu Cosmic):
status: Confirmed → Fix Committed
Changed in gnome-software (Ubuntu Bionic):
status: New → Triaged
importance: Undecided → High
Changed in gnome-software (Ubuntu Cosmic):
importance: Medium → High
assignee: nobody → Robert Ancell (robert-ancell)
Changed in gnome-software (Ubuntu Bionic):
assignee: nobody → Robert Ancell (robert-ancell)
status: Triaged → In Progress
affects: gnome-software (Ubuntu Bionic) → snapd-glib (Ubuntu Bionic)
Changed in snapd-glib (Ubuntu Bionic):
assignee: Robert Ancell (robert-ancell) → nobody
description: updated
Changed in snapd-glib (Ubuntu Bionic):
assignee: nobody → Robert Ancell (robert-ancell)
Revision history for this message
Łukasz Zemczak (sil2100) wrote : Proposed package upload rejected

An upload of snapd-glib to bionic-proposed has been rejected from the upload queue for the following reason: "Unmentioned feature additions in source - are those required to fix the bug in question? If yes, please clarify on the bug. If not, please fill in a bug for the feature and attach in the changelog.".

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

For LTS releases new features aren't necessarily a bad thing - but if there are any, those need to be properly documented with SRU paperwork if not stated otherwise by an SRU exception. The bug should include rationale as of why the change is needed in the given LTS.

Changed in snapd-glib (Ubuntu Bionic):
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package snapd-glib - 1.41-0ubuntu1

---------------
snapd-glib (1.41-0ubuntu1) cosmic; urgency=medium

  * New upstream release

 -- Robert Ancell <email address hidden> Fri, 01 Jun 2018 15:49:46 +1200

Changed in snapd-glib (Ubuntu Cosmic):
status: Fix Committed → Fix Released
Revision history for this message
Brian Murray (brian-murray) wrote : Please test proposed package

Hello errors.ubuntu.com, or anyone else affected,

Accepted snapd-glib into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/snapd-glib/1.41-0ubuntu0.18.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-needed verification-needed-bionic
Revision history for this message
Sebastien Bacher (seb128) wrote :

1.41-0ubuntu0.18.04.1 works without visible issue

tags: added: verification-done verification-done-bionic
removed: verification-needed verification-needed-bionic
Revision history for this message
Łukasz Zemczak (sil2100) wrote : Update Released

The verification of the Stable Release Update for snapd-glib has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package snapd-glib - 1.41-0ubuntu0.18.04.1

---------------
snapd-glib (1.41-0ubuntu0.18.04.1) bionic; urgency=medium

  * New upstream release:
    - Fix buffer overflows reading HTTP chunked data (LP: #1740865)
    - Support new snapd API (LP: #1774565) (LP: #1774566)

 -- Robert Ancell <email address hidden> Fri, 01 Jun 2018 16:03:26 +1200

Changed in snapd-glib (Ubuntu Bionic):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.