RFC: Should the linker warn about and/or control the propagation of audit libraries ?
Sam James
sam@gentoo.org
Wed Jul 29 17:34:40 GMT 2026
Nick Clifton <nickc@redhat.com> writes:
> Hi Guys,
>
> I am using an AI tool to look for potential security issues in the
> binutils sources. (Note - I am not using the tool to fix any
> problems, just report them). It has raised an interesting issue:
>
> The linker automatically reads DT_AUDIT entries from all
> input shared libraries and adds them as DT_DEPAUDIT entries
> in the output binary, with no warning. DT_DEPAUDIT causes
> ld.so to load the named audit library at runtime, which can
> intercept all symbol resolutions via the rtld-audit interface
> (la_symbind, la_pltenter, etc.).
>
> A malicious shared library provided as a dependency (e.g.,
> through a compromised package repository) can cause all
> binaries linked against it to automatically load an attacker
> controlled audit library at runtime, without any special
> linker flags and with no diagnostic output. The user never
> requested this — it is silently introduced in the output.
I'm not sure I see a problem: the same issue exists with ELF
constructors without DT_AUDIT.
>
> I am wonder what, if anything, we should do about this. The obvious
> thing to do would be to add a new command line option, something like:
>
> --audit-library-propogation=[default|silent|warn|refuse]
>
That said, the use of DT_AUDIT is so unusual that I'd find a message
about it slightly interesting.
> which would either silently propagate the libraries (ie the current
> behaviour) or copy them, but also issue a warning message when it does
> so, or refuse to copy them and issue error messages instead. The
> default behaviour could also be controlled by a configure time option.
>
> Is this going too far ? Would it even be helpful ? What do you think.
>
> Cheers
> Nick
>
thanks,
sam
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 418 bytes
Desc: not available
URL: <https://sourceware.org/pipermail/binutils/attachments/20260729/a9e7d3f9/attachment.sig>
More information about the Binutils
mailing list