Repository navigation
fix: Use Correct ptr Type to Avoid UAF - #433
Conversation
This change changes the managed pointer type used to manage the lifecyle of the stub instance from unique to shared. This avoids the dereference of the oft used unique pointer reference after the unique pointer has been free / deallocated.
Adding a destroy instance function to stub to force invalidate the shared ptr.
|
Copyrights |
Good catch, thanks. Fixed up. |
|
@whoisj In our old python_backend version, Stub::GetOrCreateInstance() returns std::unique_ptr&. The main thread runs Our core shows: The faulting instruction is Another thread: So it looks like the health thread destroys Stub/SharedMemoryManager and unmaps shm while the main thread is still blocked in sem_wait on Does this commit’s change from |
This change changes the managed pointer type used to manage the lifecyle of the stub instance from unique to shared. This avoids the dereference of the oft used unique pointer reference after the unique pointer has been free / deallocated.
CI Pipeline ID: 46362355