Hi Sujal, Thanks for the patch, it has been merged.
Aaron On Sun, Sep 20, 2026 at 6:05 AM Sujal Tuladhar <[email protected]> wrote: > > Hi, > > The attached patch fixes a 4-byte out-of-bounds read in eu-readelf's > print_gdb_index_section when parsing an attacker-controlled .gdb_index > section (bugzilla PR tools/34596, with reproducer). > > In the symbol-table loop the constant-pool offset "vector" from the file is > validated only with (size_t)(dataend - const_start) < vector, which permits > vector == dataend - const_start, i.e. readcus == dataend. The following > fixed-width read then reads 4 bytes at readcus, up to 4 bytes past the > section. The inner loop already guards its read with readcus + 4 > dataend, > and the sec_offset/str_offsets paths use the same (end - ptr) < width idiom; > only this initial count read omitted the read-width term. The patch adds it. > > Reproducible with eu-readelf --debug-dump=gdb_index on a crafted ELF whose > .gdb_index (version 4-9) symbol slot sets vector to the constant-pool size; > ASAN reports a heap-buffer-overflow READ of size 4. The patch (git > format-patch, applies on HEAD 947b2d9) is attached and is also on bug 34596 > as attachment 16975. > > Thanks, > Sujal Tuladhar
