New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 612613 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
please use my google.com address
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Chrome , Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Heap buffer overflows from unchecked payload_size in mojo::edj::BrokerHost::OnChannelMessage

Project Member Reported by och...@chromium.org, May 17 2016

Issue description

mojo::edk::BrokerHost::OnChannelMessage has similar issues to the previously reported bugs -- |payload| is derefed and used without checking |payload_size|.
 
Project Member

Comment 1 by bugdroid1@chromium.org, May 18 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/6c167254182506e10fe2fa9fa24d233da620b204

commit 6c167254182506e10fe2fa9fa24d233da620b204
Author: rockot <rockot@chromium.org>
Date: Wed May 18 01:03:46 2016

[mojo-edk] Fix potential buffer overflow in BrokerHost

BUG= 612613 
R=ochang@chromium.org

Review-Url: https://codereview.chromium.org/1983363002
Cr-Commit-Position: refs/heads/master@{#394303}

[modify] https://crrev.com/6c167254182506e10fe2fa9fa24d233da620b204/mojo/edk/system/broker_host_posix.cc

Comment 2 by roc...@chromium.org, May 18 2016

Status: Fixed (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, May 18 2016

Labels: Merge-Triage M-51 M-50 M-52
Adding Merge-Triage label for tracking purposes.

Once your fix had sufficient bake time (on canary, dev as appropriate), please nominate your fix for merge by adding the Merge-Request-XX label, where XX is the Chrome milestone.

When your merge is approved by the release manager, please start merging with higher milestone label first. Make sure to re-request merge for every milestone in the label list. You can get branch information on omahaproxy.appspot.com.

Your fix is very close to the branch point. After the branch happens, please make sure to check if your fix is in.

- Your friendly ClusterFuzz
Project Member

Comment 4 by sheriffbot@chromium.org, May 18 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify

Comment 5 by roc...@chromium.org, May 21 2016

Labels: Merge-Request-51

Comment 6 by tin...@google.com, May 21 2016

Labels: -Merge-Request-51 Merge-Review-51 Hotlist-Merge-Review
[Automated comment] Less than 2 weeks to go before stable on M51, manual review required.

Comment 7 by gov...@chromium.org, May 23 2016

Cc: sshruthi@chromium.org
Is this bug applicable to specific OS or all os?

Also before we approve merge to M51, Could you please confirm whether this change is baked/verified in Canary and safe to merge?

Comment 8 by gov...@chromium.org, May 23 2016

Cc: timwillis@chromium.org

Comment 9 by roc...@chromium.org, May 23 2016

The change is baked, verified, and safe to merge.

It applies to Linux, Chrome OS, Android, and Mac. Does not affect Windows.
Labels: -Merge-Review-51 Merge-Approved-51 OS-Android OS-Chrome OS-Linux OS-Mac
Approving merge to M51 branch 2704 based on comment #9. Please merge before 5:00 PM PST today (Monday) in order to make it to M51 Desktop Stable cut. Thank you.
Project Member

Comment 11 by bugdroid1@chromium.org, May 23 2016

Labels: -merge-approved-51 merge-merged-2704
The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/4fcb6e3ec5ca9b16e584f7c54bd8c163c302e2ca

commit 4fcb6e3ec5ca9b16e584f7c54bd8c163c302e2ca
Author: Ken Rockot <rockot@chromium.org>
Date: Mon May 23 17:47:48 2016

[mojo-edk] Fix potential buffer overflow in BrokerHost

BUG= 612613 
R=ochang@chromium.org

Review-Url: https://codereview.chromium.org/1983363002
Cr-Commit-Position: refs/heads/master@{#394303}
(cherry picked from commit 6c167254182506e10fe2fa9fa24d233da620b204)

Review URL: https://codereview.chromium.org/2001213002 .

Cr-Commit-Position: refs/branch-heads/2704@{#635}
Cr-Branched-From: 6e53600def8f60d8c632fadc70d7c1939ccea347-refs/heads/master@{#386251}

[modify] https://crrev.com/4fcb6e3ec5ca9b16e584f7c54bd8c163c302e2ca/mojo/edk/system/broker_host_posix.cc

Labels: -Merge-Triage Release-0-M51
Project Member

Comment 13 by sheriffbot@chromium.org, Aug 24 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 15 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic
Project Member

Comment 17 by sheriffbot@chromium.org, Jul 28

Labels: Pri-1

Sign in to add a comment