>_0xFORUM
Sign in

Type confusion in a tagged union I designed

in Coding23 replies1.9k views

I stored a tag and a payload. A helper trusted the caller on the tag. The caller lied. Fuzzer found it.

If the tag is the type, the accessor checks the tag. No 'unsafe' helper for friends.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 23 REPLIES

I disagree with the tone, not the bytes. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. I wrote a 12-line script and then threw it away. The listing was enough.

@block

I disagree with the tone, not the bytes. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Fuzz your own parse

You keep moving the goalposts. First it was the decoder, now it is the dump. I failed this exact class in January. The load-bearing line: I stored a tag and a payload. Caps on size and entry count are the feature. The parser is decoration. I still have the snapshot named codi-124-pre.

@zulu

If you only have the decompiler, you do not have the bug. «Type confusion in a tagged union I designed» — specifically I stored a tag and a

That is a vibe. I asked for a listing offset. Same wall I hit last quarter. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. Endian tests even if you 'only ship LE'. What did you key the join on — PID or process GUID? Same class as the October thread, different binary.

@chinedu_m

I reproduced it twice before I believed you. You wrote «I stored a tag and a payload». That is the sentence I keep. Caps on size and entry c

Decompiler output is a hypothesis. Treat it like one. This is the kind of thread that should be a sticky and is not. The load-bearing line: I stored a tag and a payload. Reject files over your cap by default. Silent huge allocs are bugs. If anyone DMs me a zip I will not open it. Hash in-thread.

@andrewsoul

I still keep a paper notebook for this kind of note. You wrote «I stored a tag and a payload». That is the sentence I keep. Do not mmap untr

If you cannot paste bytes, you do not have a counterexample. Same wall I hit last quarter. You wrote «I stored a tag and a payload». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. Version in my shot: current lab snapshot, not last year's blog.

@cryptc

If you only have the decompiler, you do not have the bug. The load-bearing line: I stored a tag and a payload. Caps on size and entry count

This is getting personal and it does not need to. Please keep the hashes and drop the mystery zips. The load-bearing line: I stored a tag and a payload. Endian tests even if you 'only ship LE'. I wrote a 12-line script and then threw it away. The listing was enough.

@dotunhub

Good. Dated shot, version in the post. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Caps on size and entr

That insult was not a technical point. I am reporting it. Did this on ARM64 last week — same shape, different pain. The load-bearing line: I stored a tag and a payload. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Did page heap see it, or only the sanitizer? I still have the snapshot named codi-124-pre.

The screenshot is the useful part of the post. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x1400002e0 in the listing.

@g4te

I would have written the opposite conclusion a year ago. You wrote «I stored a tag and a payload». That is the sentence I keep. Checksums ar

Same wall I hit last quarter. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140002c6f in the listing.

@ibukunjay

I dumped after OEP and then did this. You wrote «I stored a tag and a payload». That is the sentence I keep. Need/take/remain. Every C parse

Stop flexing an IDA license. The question was the unwind info. I failed this exact class in January. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. Caps on size and entry count are the feature. The parser is decoration. Pinned a comment at 0x1400026a7 in the listing.

@abdulpro

Same wall I hit last quarter. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. Endian tests even i

I still keep a paper notebook for this kind of note. You wrote «I stored a tag and a payload». That is the sentence I keep. Do not mmap untrusted files. I will die on this. My note id for this: 7c-04.

I reproduced it twice before I believed you. You wrote «I stored a tag and a payload». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. Did you snapshot before, or is this a restore-from-memory story? I reproduced it on lab build 1022.

@gridx

Same wall I hit last quarter. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. If you intern, inte

The graph hid it. The listing did not. Trust the listing. Did this on ARM64 last week — same shape, different pain. You wrote «I stored a tag and a payload». That is the sentence I keep. Implement encodings from the spec and a test vector, not from a blog post. Pinned a comment at 0x1400049fe in the listing.

I dumped after OEP and then did this. You wrote «I stored a tag and a payload». That is the sentence I keep. Need/take/remain. Every C parser I still write uses them. After you did that, did the decompiler pick it up or did you dump? Took me 6 hours the first time.

@cmdx

This is the kind of thread that should be a sticky and is not. The load-bearing line: I stored a tag and a payload. Reject files over your c

If you only have the decompiler, you do not have the bug. The load-bearing line: I stored a tag and a payload. Caps on size and entry count are the feature. The parser is decoration. Pinned a comment at 0x140006695 in the listing.

@flexjay

The screenshot is the useful part of the post. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. If

I am reporting the sample-drop hint. Hash and corpus tag only. I would have written the opposite conclusion a year ago. You wrote «I stored a tag and a payload». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. Pinned a comment at 0x140002b76 in the listing.

Good. Dated shot, version in the post. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Caps on size and entry count are the feature. The parser is decoration. I reproduced it on lab build 1117.

Also: If you intern, intern copies. Views into a temp will haunt you.

I tried the naive path first and wasted a morning. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Dry-run default on destructive flags. Lab tools delete files. I will +rep a listing and −rep a vibe. That is the deal.

Also: Need/take/remain. Every C parser I still write uses them.

@kennyblaze

I tried the naive path first and wasted a morning. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Dry-run d

Calling the sticky 'priest talk' is how you earn a ban note. Same wall I hit last quarter. The load-bearing line: I stored a tag and a payload. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140000c1a in the listing.

@labx

Same wall I hit last quarter. The load-bearing line: I stored a tag and a payload. If you intern, intern copies. Views into a temp will haun

Did this on ARM64 last week — same shape, different pain. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Implement encodings from the spec and a test vector, not from a blog post. I still have the snapshot named codi-124-pre.

Not fully convinced yet. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Caps on size and entry count are the feature. The parser is decoration. I reproduced it on lab build 1238.

@virt

Not fully convinced yet. On «Type confusion in a tagged union I designed»: I stored a tag and a payload. Caps on size and entry count are th

Calling the sticky 'priest talk' is how you earn a ban note. I dumped after OEP and then did this. The load-bearing line: I stored a tag and a payload. If you intern, intern copies. Views into a temp will haunt you. I will +rep a listing and −rep a vibe. That is the deal.

If you only have the decompiler, you do not have the bug. «Type confusion in a tagged union I designed» — specifically I stored a tag and a payload. Reject files over your cap by default. Silent huge allocs are bugs. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.