Hi Mark, Great, thanks for the review and for pushing it.
Best, Matěj On Sat, 12 Sept 2026, 21:07 Mark Wielaard, <[email protected]> wrote: > Hi Matej, > > On Sat, Sep 12, 2026 at 03:27:17PM +0200, Matej Smycka wrote: > > elf_from_remote_memory allocates a buffer of contents_size and then > > writes the ELF header into it. When the last PT_LOAD has p_filesz 0 > > (and p_memsz nonzero) contents_size collapses to zero and the 52/64 > > byte header is written past the allocation. Reject the image before > > allocating when contents_size is smaller than the header. > > This looks correct. > > > This > > completes commit 2ee961ba, which bounded the segment copies; the header > > write is the remaining out-of-bounds path. > > Hope we got them all now. > > > * libdwfl/elf-from-memory.c (elf_from_remote_memory): Goto bad_elf > > when contents_size is smaller than the Ehdr. > > > > Signed-off-by: Matej Smycka <[email protected]> > > --- > > libdwfl/elf-from-memory.c | 5 +++++ > > 1 file changed, 5 insertions(+) > > > > diff --git a/libdwfl/elf-from-memory.c b/libdwfl/elf-from-memory.c > > index 775d5a1f..4015efd2 100644 > > --- a/libdwfl/elf-from-memory.c > > +++ b/libdwfl/elf-from-memory.c > > @@ -282,6 +282,11 @@ elf_from_remote_memory (GElf_Addr ehdr_vma, > > else > > contents_size = segments_end; > > > > + /* Make sure the image is big enough for the ELF header written out > > + below; otherwise the elfNN_xlatetof of the header overflows it. */ > > + if (contents_size < (class32 ? sizeof ehdr.e32 : sizeof ehdr.e64)) > > + goto bad_elf; > > + > > free (buffer); > > the goto bad_elf does a free (buffer) so this doesn't leak. > > Pushed as https://sourceware.org/cgit/elfutils/commit/?id=7961c9813a9e > > Thanks, > > Mark >
