Skip to content

MDEV-40184 Heap-use-after-free in stored procedure when LEFT(CONCAT(...)) result is reused by LOCATE() - #5800

Open
KhaledR57 wants to merge 1 commit into
11.4from
11.4-MDEV-40184
Open

KhaledR57 wants to merge 1 commit into
11.4from
11.4-MDEV-40184

Conversation

@KhaledR57

Copy link
Copy Markdown
Contributor

LEFT(), RIGHT() and SUBSTR() returned tmp_value pointing into the buffer passed by the caller, without owning it. When a merged derived column is used twice, e.g. LOCATE(a, x, a), the second evaluation of the same item comes from Item_str_func::val_int(), which passes a local buffer. tmp_value is re-pointed into that buffer, the buffer is freed on return, and the first result becomes dangling.

Copy the result into tmp_value instead.

…..)) result is reused by LOCATE()

LEFT(), RIGHT() and SUBSTR() returned tmp_value pointing into the
buffer passed by the caller, without owning it. When a merged derived
column is used twice, e.g. LOCATE(a, x, a), the second evaluation of
the same item comes from Item_str_func::val_int(), which passes a
local buffer. tmp_value is re-pointed into that buffer, the buffer is
freed on return, and the first result becomes dangling.

Copy the result into tmp_value instead, as MDEV-32758 did for TRIM().
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

1 participant