Hi,

The attached patch fixes a 4-byte out-of-bounds read in eu-readelf's
print_gdb_index_section when parsing an attacker-controlled .gdb_index
section (bugzilla PR tools/34596, with reproducer).

In the symbol-table loop the constant-pool offset "vector" from the file is
validated only with (size_t)(dataend - const_start) < vector, which permits
vector == dataend - const_start, i.e. readcus == dataend. The following
fixed-width read then reads 4 bytes at readcus, up to 4 bytes past the
section. The inner loop already guards its read with readcus + 4 > dataend,
and the sec_offset/str_offsets paths use the same (end - ptr) < width
idiom; only this initial count read omitted the read-width term. The patch
adds it.

Reproducible with eu-readelf --debug-dump=gdb_index on a crafted ELF whose
.gdb_index (version 4-9) symbol slot sets vector to the constant-pool size;
ASAN reports a heap-buffer-overflow READ of size 4. The patch (git
format-patch, applies on HEAD 947b2d9) is attached and is also on bug 34596
as attachment 16975.

Thanks,
Sujal Tuladhar

Attachment: 0001-readelf-fix-gdb_index-cuvector-oob.patch
Description: Binary data

Reply via email to