https://gcc.gnu.org/bugzilla/show_bug.cgi?id=127038
Bug ID: 127038
Summary: [17 Regression] ASAN reports heap-buffer-overflow in
gcov
Product: gcc
Version: 17.0
Status: UNCONFIRMED
Keywords: needs-bisection
Severity: normal
Priority: P3
Component: gcov-profile
Assignee: unassigned at gcc dot gnu.org
Reporter: pheeck at gcc dot gnu.org
Blocks: 86656
Target Milestone: ---
Host: x86_64-pc-linux-gnu
Target: x86_64-pc-linux-gnu
Configure gcc using --with-build-config=bootstrap-asan:
configure --enable-languages=default,jit,lto,go,d --enable-host-shared
--enable-checking=release --disable-multilib --with-build-config=bootstrap-asan
Build GCC and run the gcov-39.c testcase:
In the build directory:
make check RUNTESTFLAGS='gcov.exp=gcov-39.c'
When I do this, address sanitizer reports a buffer overflow
==949294==ERROR: AddressSanitizer: heap-buffer-overflow on address
0x7c1eb85e2934 at pc 0x0000005816d4 bp 0x7fff3f9d9120 sp 0x7fff3f9d9118
READ of size 4 at 0x7c1eb85e2934 thread T0
#0 0x0000005816d3 in tombstone_subsequence_p
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1018
#1 0x0000005816d3 in subsumed_by_any_p
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1063
#2 0x0000005816d3 in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1096
#3 0x0000005816d3 in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1072
#4 0x000000590bdc in process_all_functions
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:2133
#5 0x00000040f9c4 in main
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1338
#6 0x7feeb922b4fd in __libc_start_call_main (/lib64/libc.so.6+0x2b4fd)
(BuildId: 23df1cec07f2b2015212729aa5a415b57861b6fe)
#7 0x7feeb922b62a in __libc_start_main_alias_2 (/lib64/libc.so.6+0x2b62a)
(BuildId: 23df1cec07f2b2015212729aa5a415b57861b6fe)
#8 0x000000413094 in _start ../sysdeps/x86_64/start.S:115
0x7c1eb85e2934 is located 0 bytes after 20-byte region
[0x7c1eb85e2920,0x7c1eb85e2934)
allocated by thread T0 here:
#0 0x0000004fd7af in operator new(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/build/libsanitizer/asan/asan_new_delete.cpp:109
#1 0x00000057bf4d in std::__new_allocator<unsigned int>::allocate(unsigned
long, void const*)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/new_allocator.h:172
#2 0x00000057bf4d in std::allocator<unsigned int>::allocate(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/allocator.h:206
#3 0x00000057bf4d in std::allocator_traits<std::allocator<unsigned int>
>::allocate(std::allocator<unsigned int>&, unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/alloc_traits.h:649
#4 0x00000057bf4d in std::_Vector_base<unsigned int,
std::allocator<unsigned int> >::_M_allocate_at_least(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/stl_vector.h:430
#5 0x00000057bf4d in std::vector<unsigned int, std::allocator<unsigned int>
>::reserve(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/vector.tcc:82
#6 0x00000057bf4d in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1084
#7 0x00000057bf4d in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1072
SUMMARY: AddressSanitizer: heap-buffer-overflow
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1018 in
tombstone_subsequence_p
Shadow bytes around the buggy address:
0x7c1eb85e2680: fd fd fd fd fa fa fd fd fd fd fa fa 00 00 00 00
0x7c1eb85e2700: fa fa 00 00 00 fa fa fa 00 00 04 fa fa fa 00 00
0x7c1eb85e2780: 04 fa fa fa 00 00 04 fa fa fa 00 00 04 fa fa fa
0x7c1eb85e2800: 00 00 04 fa fa fa 00 00 04 fa fa fa 00 00 04 fa
0x7c1eb85e2880: fa fa 00 00 00 00 fa fa 00 00 00 fa fa fa 00 00
=>0x7c1eb85e2900: 04 fa fa fa 00 00[04]fa fa fa 00 00 04 fa fa fa
0x7c1eb85e2980: 00 00 04 fa fa fa 00 00 04 fa fa fa 00 00 04 fa
0x7c1eb85e2a00: fa fa 00 00 04 fa fa fa 00 00 00 00 fa fa 00 00
0x7c1eb85e2a80: 04 fa fa fa 00 00 04 fa fa fa fa fa fa fa fa fa
0x7c1eb85e2b00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x7c1eb85e2b80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==949294==ABORTING
Referenced Bugs:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=86656
[Bug 86656] [meta-bug] Issues found with -fsanitize=address