Hi, The attached patch fixes a 4-byte out-of-bounds read in eu-readelf's print_gdb_index_section when parsing an attacker-controlled .gdb_index section (bugzilla PR tools/34596, with reproducer).
In the symbol-table loop the constant-pool offset "vector" from the file is validated only with (size_t)(dataend - const_start) < vector, which permits vector == dataend - const_start, i.e. readcus == dataend. The following fixed-width read then reads 4 bytes at readcus, up to 4 bytes past the section. The inner loop already guards its read with readcus + 4 > dataend, and the sec_offset/str_offsets paths use the same (end - ptr) < width idiom; only this initial count read omitted the read-width term. The patch adds it. Reproducible with eu-readelf --debug-dump=gdb_index on a crafted ELF whose .gdb_index (version 4-9) symbol slot sets vector to the constant-pool size; ASAN reports a heap-buffer-overflow READ of size 4. The patch (git format-patch, applies on HEAD 947b2d9) is attached and is also on bug 34596 as attachment 16975. Thanks, Sujal Tuladhar
0001-readelf-fix-gdb_index-cuvector-oob.patch
Description: Binary data
