Full Disclosure mailing list archives

Re: ODR violation in Redis Raft


From: Jeffrey Walton <noloader () gmail com>
Date: Wed, 17 Jan 2024 15:39:19 -0500

On Wed, Jan 17, 2024 at 3:29 PM Meng Ruijie <ruijie_meng () u nus edu> wrote:

[Suggested description]
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component 
hiredisAllocFns at /opt/fs/redisraft/deps/hiredis/alloc.c.

[VulnerabilityType Other]
AddressSanitizer: odr-violation

[Vendor of Product]
Redis

[Affected Product Code Base]
raft - master-1b8bd86 to master-7b46079

[Affected Component]
affected executable

[Attack Type]
Remote

[Impact Code execution]
true

[Impact Denial of Service]
true

[Attack Vectors]
run redis with redisraft

[Reference]
https://github.com/RedisLabs/redisraft/issues/600

[Has vendor confirmed or acknowledged the vulnerability?]
true

[Discoverer]
jerrytesting

I fail to see how a One Definition Rule (ODR) violation results in a
Remote Code Execution.

Can you share your PoC, please?

Jeff
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread: