[PATCH] readelf: fix 4-byte out-of-bounds read of CU-vector count in print_gdb_index_section

Aaron Merey amerey@redhat.com
Mon Sep 21 00:42:07 GMT 2026


Hi Sujal,

Thanks for the patch, it has been merged.

Aaron

On Sun, Sep 20, 2026 at 6:05 AM Sujal Tuladhar
<sujaltuladhar1231@gmail.com> wrote:
>
> Hi,
>
> The attached patch fixes a 4-byte out-of-bounds read in eu-readelf's print_gdb_index_section when parsing an attacker-controlled .gdb_index section (bugzilla PR tools/34596, with reproducer).
>
> In the symbol-table loop the constant-pool offset "vector" from the file is validated only with (size_t)(dataend - const_start) < vector, which permits vector == dataend - const_start, i.e. readcus == dataend. The following fixed-width read then reads 4 bytes at readcus, up to 4 bytes past the section. The inner loop already guards its read with readcus + 4 > dataend, and the sec_offset/str_offsets paths use the same (end - ptr) < width idiom; only this initial count read omitted the read-width term. The patch adds it.
>
> Reproducible with eu-readelf --debug-dump=gdb_index on a crafted ELF whose .gdb_index (version 4-9) symbol slot sets vector to the constant-pool size; ASAN reports a heap-buffer-overflow READ of size 4. The patch (git format-patch, applies on HEAD 947b2d9) is attached and is also on bug 34596 as attachment 16975.
>
> Thanks,
> Sujal Tuladhar



More information about the Elfutils-devel mailing list