https://gcc.gnu.org/bugzilla/show_bug.cgi?id=127038

            Bug ID: 127038
           Summary: [17 Regression] ASAN reports heap-buffer-overflow in
                    gcov
           Product: gcc
           Version: 17.0
            Status: UNCONFIRMED
          Keywords: needs-bisection
          Severity: normal
          Priority: P3
         Component: gcov-profile
          Assignee: unassigned at gcc dot gnu.org
          Reporter: pheeck at gcc dot gnu.org
            Blocks: 86656
  Target Milestone: ---
              Host: x86_64-pc-linux-gnu
            Target: x86_64-pc-linux-gnu

Configure gcc using --with-build-config=bootstrap-asan:

configure --enable-languages=default,jit,lto,go,d --enable-host-shared
--enable-checking=release --disable-multilib --with-build-config=bootstrap-asan

Build GCC and run the gcov-39.c testcase:

In the build directory:
make check RUNTESTFLAGS='gcov.exp=gcov-39.c'

When I do this, address sanitizer reports a buffer overflow

==949294==ERROR: AddressSanitizer: heap-buffer-overflow on address
0x7c1eb85e2934 at pc 0x0000005816d4 bp 0x7fff3f9d9120 sp 0x7fff3f9d9118
READ of size 4 at 0x7c1eb85e2934 thread T0
    #0 0x0000005816d3 in tombstone_subsequence_p
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1018
    #1 0x0000005816d3 in subsumed_by_any_p
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1063
    #2 0x0000005816d3 in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1096
    #3 0x0000005816d3 in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1072
    #4 0x000000590bdc in process_all_functions
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:2133
    #5 0x00000040f9c4 in main
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1338
    #6 0x7feeb922b4fd in __libc_start_call_main (/lib64/libc.so.6+0x2b4fd)
(BuildId: 23df1cec07f2b2015212729aa5a415b57861b6fe)
    #7 0x7feeb922b62a in __libc_start_main_alias_2 (/lib64/libc.so.6+0x2b62a)
(BuildId: 23df1cec07f2b2015212729aa5a415b57861b6fe)
    #8 0x000000413094 in _start ../sysdeps/x86_64/start.S:115

0x7c1eb85e2934 is located 0 bytes after 20-byte region
[0x7c1eb85e2920,0x7c1eb85e2934)
allocated by thread T0 here:
    #0 0x0000004fd7af in operator new(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/build/libsanitizer/asan/asan_new_delete.cpp:109
    #1 0x00000057bf4d in std::__new_allocator<unsigned int>::allocate(unsigned
long, void const*)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/new_allocator.h:172
    #2 0x00000057bf4d in std::allocator<unsigned int>::allocate(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/allocator.h:206
    #3 0x00000057bf4d in std::allocator_traits<std::allocator<unsigned int>
>::allocate(std::allocator<unsigned int>&, unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/alloc_traits.h:649
    #4 0x00000057bf4d in std::_Vector_base<unsigned int,
std::allocator<unsigned int> >::_M_allocate_at_least(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/stl_vector.h:430
    #5 0x00000057bf4d in std::vector<unsigned int, std::allocator<unsigned int>
>::reserve(unsigned long)
/home/worker/buildworker/tiber-gcc-asan/objdir/prev-x86_64-pc-linux-gnu/libstdc++-v3/include/bits/vector.tcc:82
    #6 0x00000057bf4d in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1084
    #7 0x00000057bf4d in path_info::suppress_blocks(std::vector<bool,
std::allocator<bool> > const&)
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1072

SUMMARY: AddressSanitizer: heap-buffer-overflow
/home/worker/buildworker/tiber-gcc-asan/build/gcc/gcov.cc:1018 in
tombstone_subsequence_p
Shadow bytes around the buggy address:
  0x7c1eb85e2680: fd fd fd fd fa fa fd fd fd fd fa fa 00 00 00 00
  0x7c1eb85e2700: fa fa 00 00 00 fa fa fa 00 00 04 fa fa fa 00 00
  0x7c1eb85e2780: 04 fa fa fa 00 00 04 fa fa fa 00 00 04 fa fa fa
  0x7c1eb85e2800: 00 00 04 fa fa fa 00 00 04 fa fa fa 00 00 04 fa
  0x7c1eb85e2880: fa fa 00 00 00 00 fa fa 00 00 00 fa fa fa 00 00
=>0x7c1eb85e2900: 04 fa fa fa 00 00[04]fa fa fa 00 00 04 fa fa fa
  0x7c1eb85e2980: 00 00 04 fa fa fa 00 00 04 fa fa fa 00 00 04 fa
  0x7c1eb85e2a00: fa fa 00 00 04 fa fa fa 00 00 00 00 fa fa 00 00
  0x7c1eb85e2a80: 04 fa fa fa 00 00 04 fa fa fa fa fa fa fa fa fa
  0x7c1eb85e2b00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x7c1eb85e2b80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
==949294==ABORTING


Referenced Bugs:

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=86656
[Bug 86656] [meta-bug] Issues found with -fsanitize=address

Reply via email to