ExportXMLWordPrintableJSON

    • Type: Bug
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: BSON
    • None
    • None
    • Python Drivers
    • None
    • None
    • None
    • None
    • None
    • None

      Body:

      Detailed steps to reproduce the problem?

      Include full traceback, if possible

      A document declares size 8. A Boolean field needs 4 bytes of element data (type, key, key terminator, value), but only 3 bytes are available before the document terminator. The value byte at position 7 is the same byte as the document terminator, and the C extension decodes the document instead of rejecting it.

      >>> import bson
      >>> data = b'\x08\x00\x00\x00\x08a\x00\x00'
      >>> bson.decode(data)
      {'a': False}
      >>> bson.is_valid(data)
      True
      

      The same overlap triggers with Regex (type 0x0b), where the flags string terminator doubles as the document terminator:

      >>> bson.decode(b'\x08\x00\x00\x00\x0ba\x00\x00')
      {'a': Regex('', 0)}
      

      The pure-Python decoder rejects both inputs with InvalidBSON: bad object or element length.

      The Boolean handler in bson/_cbsonmodule.c reads its value byte without checking max. The Regex handler checks max < pattern_length + flags_length, which permits the flags terminator to consume the last byte of the document. The bug has been present since PyMongo 1.9.0.

      Definition of done: what must be done to consider the task complete?

      • The C extension raises InvalidBSON for documents where the last element's value would consume the document terminator byte, matching the pure-Python decoder.
      • bson.is_valid() returns False for such documents.
      • Add regression tests to cover the cases in the code samples above.

      The exact Python version used, with patch level:

      Version-independent. Observed on CPython 3.13.13; the defect is in the C extension's bounds checking, not tied to a Python version.

      The exact version of PyMongo used, with patch level:

      All releases since PyMongo 1.9.0. Observed against 4.18.0.dev0 at commit d03d621e. Requires the C extension (pymongo.has_c() is True); the pure-Python fallback is not affected.

      Describe how MongoDB is set up. Local vs Hosted, version, topology, load balanced, etc.

      Not applicable. The defect is in client-side BSON parsing and triggers before anything is sent to a server.

      The operating system and version (e.g. Windows 7, OSX 10.8, ...)

      Not applicable. Every platform using the C extension is affected.

      Web framework or asynchronous network library used, if any, with version (e.g. Django 1.7, mod_wsgi 4.3.0, gevent 1.0.1, Tornado 4.0.2, ...)

      Not applicable.

      Security Vulnerabilities

      If you’ve identified a security vulnerability in a driver or any other MongoDB project, please report it according to the instructions here

      Assessed as a correctness bug, not a security vulnerability. The misread stays within the document allocation and the decoded result is a normal dict or Regex object, so there are no memory-safety implications. The primary impact is the behavioral difference between the C and pure-Python decoders.

            Assignee:
            Unassigned
            Reporter:
            Steve Silvester
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: