[PATCH] libdwfl: Reject reconstructed image smaller than the ELF header
Matěj Smyčka
matejsmycka@gmail.com
Sat Sep 12 23:42:41 GMT 2026
Hi Mark,
Great, thanks for the review and for pushing it.
Best,
Matěj
On Sat, 12 Sept 2026, 21:07 Mark Wielaard, <mark@klomp.org> wrote:
> Hi Matej,
>
> On Sat, Sep 12, 2026 at 03:27:17PM +0200, Matej Smycka wrote:
> > elf_from_remote_memory allocates a buffer of contents_size and then
> > writes the ELF header into it. When the last PT_LOAD has p_filesz 0
> > (and p_memsz nonzero) contents_size collapses to zero and the 52/64
> > byte header is written past the allocation. Reject the image before
> > allocating when contents_size is smaller than the header.
>
> This looks correct.
>
> > This
> > completes commit 2ee961ba, which bounded the segment copies; the header
> > write is the remaining out-of-bounds path.
>
> Hope we got them all now.
>
> > * libdwfl/elf-from-memory.c (elf_from_remote_memory): Goto bad_elf
> > when contents_size is smaller than the Ehdr.
> >
> > Signed-off-by: Matej Smycka <matejsmycka@gmail.com>
> > ---
> > libdwfl/elf-from-memory.c | 5 +++++
> > 1 file changed, 5 insertions(+)
> >
> > diff --git a/libdwfl/elf-from-memory.c b/libdwfl/elf-from-memory.c
> > index 775d5a1f..4015efd2 100644
> > --- a/libdwfl/elf-from-memory.c
> > +++ b/libdwfl/elf-from-memory.c
> > @@ -282,6 +282,11 @@ elf_from_remote_memory (GElf_Addr ehdr_vma,
> > else
> > contents_size = segments_end;
> >
> > + /* Make sure the image is big enough for the ELF header written out
> > + below; otherwise the elfNN_xlatetof of the header overflows it. */
> > + if (contents_size < (class32 ? sizeof ehdr.e32 : sizeof ehdr.e64))
> > + goto bad_elf;
> > +
> > free (buffer);
>
> the goto bad_elf does a free (buffer) so this doesn't leak.
>
> Pushed as https://sourceware.org/cgit/elfutils/commit/?id=7961c9813a9e
>
> Thanks,
>
> Mark
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://sourceware.org/pipermail/elfutils-devel/attachments/20260913/fde3a878/attachment.htm>
More information about the Elfutils-devel
mailing list