T09 · Insecure Skill Coding Practices
- Location
scripts/lygo_p0_gate.py:65- Finding
File-size limit is enforced only after the entire file is loaded into memory
- Content
View full analysis
dict: if len(data) > MAX_BYTES: return { "verdict": "QUARANTINE", "phi_risk": round4(PHI_MAX), "risk": 1.0, "hash16": hashlib.sha256(data).hexdigest()[:16], } ``` ```python for arg in sys.argv[1:]: path = Path(arg) if not path.is_file(): print(f"SKIP not file: {path}") continue data = path.read_bytes() r = validate_bytes(data) ``` ### Technical Analysis The documented 8192-byte limit is checked by `validate_bytes()` only after `Path.read_bytes()` has loaded the entire file into memory. Consequently, `MAX_BYTES` limits only the data accepted by the scoring algorithm; it does not limit filesystem reads or memory allocation. An attacker who can persuade a user or agent to scan an attacker-controlled file can provide a very large regular or sparse file. The Python process will attempt to allocate enough memory for the complete contents before returning the intended `QUARANTINE` verdict. ### Attack Path 1. An attacker supplies or identifies a very large file as an input that should be checked. 2. The user or agent follows the documented workflow and runs `lygo_p0_gate.py` against it. 3. `path.read_bytes()` attempts to load the complete file. 4. The process consumes excessive memory, may be terminated by the operating system, or affects other workloads. 5. The size check and quarantine response are never reached if the allocation or read fails first. ### Impact Assessment This issue does not grant additional privileges or directly execute attacker-controlled code. Its scope is the local process and potentially the host's available memory. Successful exploitation can cause denial of service ...[truncated 92 chars]- Remediation
View remediation
MAX_BYTES: return quarantine_result ``` - Handle `OSError`, memory-related failures, and files that change while being read. - If a hash of oversized files is required, calculate it incrementally in bounded chunks rather than loading the complete file. - Add regression tests using large and sparse files to verify bounded memory usage. ]]>
