Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Summary
Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage.
When partial_value reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path calls cursor_position, which dereferences those stale pointers. This results in a heap-use-after-free and can terminate the Ruby process.
An attacker who can supply JSON stream data to an application using JSON::ResumableParser may cause process termination when the application calls partial_value on incomplete attacker-controlled input containing duplicate object keys.
The issue was reproduced in the native C extension from the official RubyGems releases:
- JSON 2.20.0
- JSON 2.21.0
- JSON 2.21.1
The attached evidence demonstrates:
- an AddressSanitizer-confirmed heap-use-after-free;
- a native
SIGSEGVusing the official JSON 2.21.1 RubyGem; - an end-to-end loopback TCP attacker/victim reproduction;
- four differential controls;
- successful execution after applying a tested patch control.
This was originally reported privately through Ruby's HackerOne program as report #3867755. A Ruby maintainer independently confirmed reproduction of the ASan failure and requested that further coordination continue through this private advisory.
No code execution or information disclosure is claimed.
Details
The affected source is:
ext/json/ext/parser/parser.c
The vulnerable sequence in JSON 2.21.1 is:
cResumableParser_parsereaches the end of the current input buffer.- It calls
json_str_clear(parser->buffer). - It sets
parser->buffer = Qfalse. - The parser-state pointers into the released buffer are not reset.
partial_valuemakes a shallow copy of the parser state.- Reconstructing an incomplete object containing duplicate keys reaches the duplicate-key warning path.
cursor_positionwalks through the stale input pointers and reads released memory.
Relevant source locations:
-
Buffer release: https://github.com/ruby/json/blob/fd61def38b9bb859fee7eec8e7d3143600e5b347/ext/json/ext/parser/parser.c#L2562-L2569
-
Parser-state copy: https://github.com/ruby/json/blob/fd61def38b9bb859fee7eec8e7d3143600e5b347/ext/json/ext/parser/parser.c#L2647-L2654
-
Stale-pointer read in
cursor_position: https://github.com/ruby/json/blob/fd61def38b9bb859fee7eec8e7d3143600e5b347/ext/json/ext/parser/parser.c#L590-L628 -
Duplicate-key handling path: https://github.com/ruby/json/blob/fd61def38b9bb859fee7eec8e7d3143600e5b347/ext/json/ext/parser/parser.c#L1196-L1255
When input is supplied to the resumable parser, the parser state stores direct pointers into the backing Ruby string:
RSTRING_GETMEM(parser->buffer, start, len);
parser->state.start = start;
parser->state.end = start + len;
parser->state.cursor = parser->state.start + offset;
After the current buffer has been consumed, cResumableParser_parse clears the string and removes the parser's reference to it:
if (eos(&parser->state)) {
json_str_clear(parser->buffer);
parser->buffer = Qfalse;
}
This path does not invalidate or replace:
parser->state.start
parser->state.cursor
parser->state.end
JSON::ResumableParser#partial_value subsequently makes a shallow copy of the parser structure:
JSON_ResumableParser *original_parser = cResumableParser_get(self);
JSON_ResumableParser parser = *original_parser;
When the partial object contains duplicate keys, reconstruction follows this call path:
cResumableParser_partial_value_body
-> json_decode_object
-> json_on_duplicate_key
-> emit_duplicate_key_warning
-> emit_parse_warning
-> cursor_position
cursor_position then reads through pointers that may refer to released storage.
AddressSanitizer reports:
ERROR: AddressSanitizer: heap-use-after-free
cursor_position at parser.c:604
freed by cResumableParser_parse at parser.c:2567
The reproducer follows the normal resumable-parser API sequence:
parser