4 ms·
This interface raw_data_->ToArrayBuffer() sometimes returns a copy of its internal buffer and sometimes returns a smart pointer to its internal buffer. See http
by xfs 8y ago
This interface raw_data_->ToArrayBuffer() sometimes returns a copy of its internal buffer and sometimes returns a smart pointer to its internal buffer. See https://github.com/chromium/chromium/blob/ba9748e78ec7e9c0d594e7edf7b2c07ea2a90449/third_party/blink/renderer/platform/wtf/typed_arrays/array_buffer_builder.h#L63-L67 https://github.com/chromium/chromium/blob/ba9748e78ec7e9c0d5...
But DOMArrayBuffer::Create() here takes ownership of the memory from ToArrayBuffer(), so in the latter case of a smart pointer, the internal buffer of raw_data_ is immediately invalidated and its value becomes undefined after creating the DOMArrayBuffer. This is fine if file loading is finished at this point because raw_data_ is reset to nullptr, but if the load is partial, then the undefined value in raw_data_ will be reused to create another DOMArrayBuffer which is then accessible in javascript. Hence the use after free.
I'll attribute the root cause of this bug to unclear memory ownership passing in interface design.