dsanders11

#52474: fix: refactor to avoid UAF in NodeStreamLoader

Merged
Created: Jul 27, 2026, 6:31:53 PM
Merged: Jul 28, 2026, 10:00:19 PM
7 comments
Target: main

Description of Change

Under specific circumstances NodeStreamLoader can hit a UAF when it deletes itself before completing NodeStreamLoader::NotifyReadable, so refactor to avoid that possibility.

Test added as a separate commit first to show the ASan failure flagging the UAF: https://github.com/electron/electron/actions/runs/30314440929/job/90138979629

Also added tests for two other edge cases which get fixed by the refactor, which would cause the streaming response to stall out: https://github.com/electron/electron/actions/runs/30321732441/job/90160483107

Checklist

Release Notes

Notes: Fixed a UAF with protocol.registerStreamProtocol when an error is emitted during a read

Backports

41-x-y
Merged
PR Number
#52513
Merged At
Jul 29, 2026, 1:01:02 AM
Released In
Not yet
Release Date
Not yet
42-x-y
Merged
PR Number
#52516
Merged At
Jul 29, 2026, 1:00:58 AM
Released In
Not yet
Release Date
Not yet
43-x-y
Merged
PR Number
#52514
Merged At
Jul 29, 2026, 1:00:54 AM
Released In
Not yet
Release Date
Not yet
44-x-y
Merged
PR Number
#52515
Merged At
Jul 29, 2026, 1:00:51 AM
Released In
Not yet
Release Date
Not yet

Semver Impact

Major
Breaking changes
Minor
New features
Patch
Bug fixes
None
Docs, tests, etc.

Semantic Versioning helps users understand the impact of updates:

  • Major (X.y.z): Breaking changes that may require code modifications
  • Minor (x.Y.z): New features that maintain backward compatibility
  • Patch (x.y.Z): Bug fixes that don't change the API
  • None: Changes that don't affect using facing parts of Electron