Hi Sujal,

Thanks for the patch, it has been merged.

Aaron

On Sun, Sep 20, 2026 at 6:05 AM Sujal Tuladhar
<[email protected]> wrote:
>
> Hi,
>
> The attached patch fixes a 4-byte out-of-bounds read in eu-readelf's 
> print_gdb_index_section when parsing an attacker-controlled .gdb_index 
> section (bugzilla PR tools/34596, with reproducer).
>
> In the symbol-table loop the constant-pool offset "vector" from the file is 
> validated only with (size_t)(dataend - const_start) < vector, which permits 
> vector == dataend - const_start, i.e. readcus == dataend. The following 
> fixed-width read then reads 4 bytes at readcus, up to 4 bytes past the 
> section. The inner loop already guards its read with readcus + 4 > dataend, 
> and the sec_offset/str_offsets paths use the same (end - ptr) < width idiom; 
> only this initial count read omitted the read-width term. The patch adds it.
>
> Reproducible with eu-readelf --debug-dump=gdb_index on a crafted ELF whose 
> .gdb_index (version 4-9) symbol slot sets vector to the constant-pool size; 
> ASAN reports a heap-buffer-overflow READ of size 4. The patch (git 
> format-patch, applies on HEAD 947b2d9) is attached and is also on bug 34596 
> as attachment 16975.
>
> Thanks,
> Sujal Tuladhar

Reply via email to