Skip to content

Reject SafeMarshal collection lengths longer than the remaining input - #9756

Open
hsbt wants to merge 1 commit into
masterfrom
claude/sharp-rosalind-6fde59
Open

Reject SafeMarshal collection lengths longer than the remaining input#9756
hsbt wants to merge 1 commit into
masterfrom
claude/sharp-rosalind-6fde59

Conversation

@hsbt

@hsbt hsbt commented Aug 4, 2026

Copy link
Copy Markdown
Member

Gem::SafeMarshal::Reader#read_integer can decode a 4-byte length of up to about 4.3 billion, and read_array, read_hash, read_hash_with_default_value, read_object_with_ivars, and read_object passed that length straight to Array.new, which allocates the backing store before any element is read. An 8-byte payload is enough to raise NoMemoryError. Reported in HackerOne 3877678 and triaged as hardening rather than a vulnerability.

Since every marshal element consumes at least one byte of input, a declared count larger than the bytes remaining in the stream can never be valid. This adds a read_count helper that raises the new LengthTooLongError in that case, and also adds the negative length check that read_hash was missing. Legitimate inputs are unaffected because the bound is derived from the input itself rather than a magic constant.

A crafted 4-byte length makes read_array and its siblings allocate the
Array.new backing store before reading a single element, so an 8-byte
payload can request gigabytes of memory (HackerOne 3877678, triaged as
hardening). Since every element consumes at least one byte, a count
larger than the remaining input bytes can never be valid. Raise the new
LengthTooLongError instead of allocating, and add the negative length
check that read_hash was missing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant