PR 34342 SIGSEGV libctf/ctf-types.c:1603

Alan Modra amodra@gmail.com
Fri Jul 3 01:06:15 GMT 2026


Lots of analysis in the PR.

	* ctf-open.c (init_static_types_internal): Sanity check variable
	length record bytes against type section length.
	(upgrade_types_v1): Likewise.  Don't check unused "size" here.

diff --git a/libctf/ctf-open.c b/libctf/ctf-open.c
index 03992ef4c1a..584d502a29e 100644
--- a/libctf/ctf-open.c
+++ b/libctf/ctf-open.c
@@ -458,13 +458,14 @@ upgrade_types_v1 (ctf_dict_t *fp, ctf_header_t *cth)
       size = get_ctt_size_v1 (fp, (const ctf_type_t *) tp, NULL, &increment);
       vbytes = get_vbytes_v1 (fp, kind, size, vlen);
 
+      if (vbytes < 0
+	  || (uintptr_t) tend - (uintptr_t) tp < (size_t) increment + vbytes)
+	return ECTF_CORRUPT;
+
       get_ctt_size_v2_unconverted (fp, (const ctf_type_t *) tp, NULL,
 				   &v2increment);
       v2bytes = get_vbytes_v2 (fp, kind, size, vlen);
 
-      if ((vbytes < 0) || (size < 0))
-	return ECTF_CORRUPT;
-
       increase += v2increment - increment;	/* May be negative.  */
       increase += v2bytes - vbytes;
     }
@@ -748,7 +749,8 @@ init_static_types_internal (ctf_dict_t *fp, ctf_header_t *cth,
       (void) ctf_get_ctt_size (fp, tp, &size, &increment);
       vbytes = LCTF_VBYTES (fp, kind, size, vlen);
 
-      if (vbytes < 0)
+      if (vbytes < 0
+	  || (uintptr_t) tend - (uintptr_t) tp < (size_t) increment + vbytes)
 	return ECTF_CORRUPT;
 
       /* For forward declarations, ctt_type is the CTF_K_* kind for the tag,

-- 
Alan Modra


More information about the Binutils mailing list