https://sourceware.org/bugzilla/show_bug.cgi?id=34705

            Bug ID: 34705
           Summary: eu-unstrip: malformed SYMTAB size can cause a heap
                    out-of-bounds write
           Product: elfutils
           Version: unspecified
            Status: UNCONFIRMED
          Severity: normal
          Priority: P2
         Component: tools
          Assignee: unassigned at sourceware dot org
          Reporter: harshit7kr at gmail dot com
                CC: elfutils-devel at sourceware dot org
  Target Milestone: ---

eu-unstrip does not validate that a SHT_SYMTAB section's sh_size is at least
sh_entsize before deriving its symbol count.

In copy_elided_sections(), the counts are computed as sh_size / sh_entsize. For
a malformed table with nonzero sh_entsize and sh_size < sh_entsize, the
quotient is zero. The subsequent total_syms expression (stripped_nsym - 1 +
unstripped_nsym - 1) underflows/wraps, so the symbols and symndx_map buffers
are too small for collect_symbols(). With the malformed table in the
debug/unstripped input, I reproduced an AddressSanitizer heap-buffer-overflow
(WRITE of size 8) in collect_symbols(), and glibc heap checking reported
corrupted size on process exit. Reversing the input roles also reaches invalid
destination arithmetic.

Reproduction used elfutils upstream commit
7b675cbdb0d1f216938b4b33aea30fd35fb1ae0a and the distribution eu-unstrip
0.195-8. The two ET_REL inputs are 552 bytes and differ only at offset 0x188,
the low byte of the .symtab sh_size: 0x60 in the valid file and 0x00 in the
malformed file. Valid input SHA-256:
8958144e15038e049f2126e8e385114854a07d50cdece0c5b3f65ee483f20455. Malformed
input SHA-256:
879da26918f390649e33782e4498a67bb3a652fdb63508b4ccab7bcba831c7dc.

Run the unpatched binary with:
MALLOC_CHECK_=3 MALLOC_PERTURB_=165 eu-unstrip -o out unstrip-A-valid.elf
unstrip-B-hostile.elf

Observed: 'corrupted size vs. prev_size' (abort). The same valid file supplied
twice exits successfully; eu-elflint reports no errors for the valid seed. The
write is bounded to one symbol and one index-map element past their
allocations. This affects a local command-line utility processing two ELF
inputs; I have not established a remote caller, privilege escalation, or code
execution.

A local candidate fix adds sh_size < sh_entsize checks before the relevant
count calculations, with a regression test. I can provide the two input files
and test patch for review.

-- 
You are receiving this mail because:
You are on the CC list for the bug.

Reply via email to