T09 · Insecure Skill Coding Practices
- Location
scripts/mesh_tool.py:27- Finding
Unbounded Resource Consumption in STL Processing
- Content
View full analysis
Vulnerability Details
File Location:
scripts/mesh_tool.py:27-39, 56-66, 83-118
Vulnerability Type: Denial of service through unbounded memory consumption and quadratic processing
Risk Level: MediumVulnerable Code:
python def _parse_ascii(self): current_triangle = [] with open(self.filepath) as f: for line in f: parts = line.strip().split() if not parts: continue if parts[0] == "vertex": v = (float(parts[1]), float(parts[2]), float(parts[3])) current_triangle.append(v) elif parts[0] == "endfacet": if len(current_triangle) == 3: # Default ID 0 self.triangles.append((current_triangle[0], current_triangle[1], current_triangle[2], 0)) current_triangle = []python def _parse_binary(self): with open(self.filepath, "rb") as f: f.read(80) # Skip header count_data = f.read(4) if not count_data: return count = struct.unpack("<I", count_data)[0] file_size = os.path.getsize(self.filepath) expected_size = 80 + 4 + (50 * count) if file_size != expected_size: raise ValueError("Size mismatch") for _ in range(count): data = f.read(50) floats = struct.unpack("<3f3f3f3f", data[:48]) attr = struct.unpack("<H", data[48:50])[0] v1 = (floats[3], floats[4], floats[5]) v2 = (floats[6], floats[7], floats[8]) v3 = (floats[9], floats[10], floats[11]) self.triangles.append((v1, v2, v3, attr))python def get_components(self): def quantize(v): return (round(v[0], 5), round(v[1], 5), round(v[2], 5)) vertex_map = collections.defaultdict(list) for i, t in enumerate(self.tri ...[truncated 2675 chars]- Remediation
View remediation
Remediation Suggestions
- Enforce a configurable maximum input-file size before opening or parsing an STL file.
- Validate the binary triangle count against a conservative configured maximum before allocating or iterating.
- Apply limits to ASCII line length, total line count, vertex count, and triangle count.
- Reject non-finite coordinates and malformed facets early.
- Redesign connected-component construction so each vertex adjacency bucket is expanded at most once, or construct deduplicated triangle adjacency before traversal.
- Avoid creating duplicate component collections containing every triangle; retain triangle indices or stream data where feasible.
- Run untrusted mesh analysis in an isolated worker with memory, CPU, and execution-time limits.
- Return a controlled error when any configured resource limit is exceeded.
