From patchwork Sun Jun 21 21:12:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Naveed Khan X-Patchwork-Id: 137512 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id A08CF4BA2E1E for ; Sun, 21 Jun 2026 21:13:02 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org A08CF4BA2E1E Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=digiscrypt.com header.i=@digiscrypt.com header.a=rsa-sha256 header.s=google header.b=KAHUNrqn X-Original-To: binutils@sourceware.org Delivered-To: binutils@sourceware.org Received: from mail-pg1-x52e.google.com (mail-pg1-x52e.google.com [IPv6:2607:f8b0:4864:20::52e]) by sourceware.org (Postfix) with ESMTPS id 9E0374BA2E0E for ; Sun, 21 Jun 2026 21:12:27 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 9E0374BA2E0E Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=digiscrypt.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=digiscrypt.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 9E0374BA2E0E Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::52e ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782076347; cv=none; b=g1HzqKFMztvg10S6KVQtJRRNibzDGK/Bti8kjgdKGb0//LZh7A1/iEIsI5A1v7bFrg5uxHAc1E61RvOjN2sBrkLcf/7oGwlJ1gTijYdfnL21gnDGMln+FDj1fAfLVIDDXxj1cF2kZXpup5Uor46MEUHWAo0Z0XJKqb2BwnQGjPw= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782076347; c=relaxed/simple; bh=nSMmaiL2BDhWdsrfaPY6EzWGdssxTi7fIExrVObxWcU=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=cwfiOTWfHZzhcodkLqAa6CsjegwKxyEtn8YLtz8MxHp1sh81syOariodTpRoNQ5aa7QbD6L/Qdocdh+v52TxXZFX9pe5T78H5DXUylwUYd0vIaNX43NFi9ty9z+7O3dGR97UOONQgH4SedSVaqhoXPC2JIUnonlCj94yp0y1sT8= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=digiscrypt.com header.i=@digiscrypt.com header.a=rsa-sha256 header.s=google header.b=KAHUNrqn DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 9E0374BA2E0E Received: by mail-pg1-x52e.google.com with SMTP id 41be03b00d2f7-c8deb37737dso163255a12.1 for ; Sun, 21 Jun 2026 14:12:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digiscrypt.com; s=google; t=1782076346; x=1782681146; darn=sourceware.org; h=mime-version:content-transfer-encoding:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to; bh=XaAJizR4LGOzTVpH/EmIJsiKGAl2SUqV+o2xaRsLrrM=; b=KAHUNrqnn0UivMhV1KptL9/OCRgK+M+EsH1aJYj7JHhPfQy+d5y3LA5YqiLXtemybe knAac7b/JkhqSPvvkG3GfTSyEW+bXB823262bOQGLxOQFR/PxpaLpgkzxByk0u/syASt BxNe80kY6XE72BPQDRGhCg0Z9pZnMi0L4RzG/0S0b9y/1Bmt1l4HhP0S9/3sGdcqeSxM nbqnPbREa5g+L9xMJeAsho9kXBIFbU6wstfW6yzcwKXnD+toqJjEVAEBjuyRQMqyXzwU hIdjT0kA7du4lzXjmUGhEy0Ns6rNAXr3m36Z5AvnCrtS6d0QWe3LBoCvC6ISFgWKrLCa 0pDg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782076346; x=1782681146; h=mime-version:content-transfer-encoding:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=XaAJizR4LGOzTVpH/EmIJsiKGAl2SUqV+o2xaRsLrrM=; b=WyDfQEsOMny/ZPbwy51u92p2T4J0zmJc5TULKAEGRIBm/JPoF7Y/r5riKEpeb6V3JG mdTBlucKo7i2IPznaoy1snS6+CYTMWOMwbGScx/h3xmpwE/AsKg8Tx+L0Nm0zSVtoTnv flhIj7UIiAeTblOOnC0fuL7dwtGQgR9l80zbUhaLcRFK4ETqfKuws6TLXGtjV7DrYTXn MzYLBu/seHnAddp45vN5TiaERruuRibnLkh4+9Piyuu0/uOMt8vjMijvN+fgou9+TqFd 6UflPGY0/L/xWFW/aMCAXRsZN4/2fFQh0rHcDzkU9/379PxCg8SB9hudpVKdmpGu8NmF gSSQ== X-Gm-Message-State: AOJu0YxMBYG9tkze/Nemlwar+JIfJ5YOrv92eyPeGnUB9QCHC99fiCjk ZIt5J4QvMF217PIEpFvioM2BonqLADyMzOmMKAF1vINAg0jvWLTt0cKFV8E92FAsD4WAsURAveJ 1rQ2OtQ14oY4= X-Gm-Gg: AfdE7cmy/LIA7jbE71RTo2cyFmXDxVeN0eEtH4flyo6hz9bQdckdoZMpsF6zRBk5Qii SKkz6gy1/9chSZDGvleQvDk/16hWmZ1oLwV5M0OsXt8VukCKfzO7ImJ+vez63/8UqyhNeFMmNWV 7pf1iGBdb465sC7QxuYLCF7ut8B15su3xvKMxaGatsPfNHQl65ZDkUqad4UasGAv5/EHLmQ2Zk8 yeKXHFWDxIi0FjRlrYFpr6zFJLvCqDSXCeJmv1d9VYqKY9rRZjYW1uWsgQdir2bqBJVUkK/6c/R M+37BcgLLpyyRUPpT2viJqtYiGuxykDtIKf0uySziCbvM0Fa+GpgBxzyAEvr8ucqHtWVoCjUSXO Rk6eS5GGAjQwal1I/ntWzazB4B+yFBUyrR8tO1V9ymAYC6HE9sFB5LGXb8Zxttr5J8wDXaj5L9B 7Fkc+hoYXGCTAfphc0rXwaX19KSzn3pb6nHm9I6ukfUHaim5PeyQMcRk8A X-Received: by 2002:a05:6a00:4649:b0:845:42b9:386b with SMTP id d2e1a72fcca58-845507bf409mr12596209b3a.12.1782076346389; Sun, 21 Jun 2026 14:12:26 -0700 (PDT) Received: from 3.1.168.192.in-addr.arpa ([2401:4900:1c07:5bb8:c9c3:ff21:7fc5:f37]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84564d8ddf1sm5399950b3a.14.2026.06.21.14.12.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 21 Jun 2026 14:12:26 -0700 (PDT) From: Naveed Khan To: binutils@sourceware.org Subject: [PATCH] libsframe: validate FDE/FRE subsection bounds in sframe_decode Date: Mon, 22 Jun 2026 02:42:22 +0530 Message-ID: <178207634240.2958.13202347064770017350@digiscrypt.com> X-CodeOps-Marker: 9fdcfe09f5d14436961ee08263f31870 MIME-Version: 1.0 X-Spam-Status: No, score=-14.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_PBL, SPF_HELO_NONE, SPF_PASS shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: binutils-bounces~patchwork=sourceware.org@sourceware.org sframe_decode only calls sframe_header_sanity_check_p, which verifies that sfh_fdeoff <= sfh_freoff but never checks the header-supplied offsets, lengths and counts against the size of the SFrame buffer. On the native-endian decode path -- the foreign-endian path is bounds checked inside flip_sframe -- a crafted SFrame section therefore drives two out-of-bounds heap reads: - sframe_fde_tbl_init reads sfh_num_fdes function descriptor entries starting at frame_buf + sfh_fdeoff, and - memcpy (dctx->sfd_fres, frame_buf + sfh_freoff, sfh_fre_len) copies sfh_fre_len bytes starting at frame_buf + sfh_freoff. Both read past the end of the buffer. The defect is reachable from objdump --sframe and readelf on an object file carrying a crafted .sframe section; for example a 28-byte section whose header claims sfh_fre_len = 0x10000 makes objdump --sframe read 64KB past the section contents. Validate in sframe_decode that the FDE and FRE sub-sections described by the header are fully contained in the buffer before they are read. The checks use subtraction and division so the arithmetic cannot overflow. Signed-off-by: Naveed Khan diff --git a/libsframe/sframe.c b/libsframe/sframe.c index cd6bb302..24d07ae3 100644 --- a/libsframe/sframe.c +++ b/libsframe/sframe.c @@ -1480,6 +1480,25 @@ sframe_decode (const char *sf_buf, size_t sf_size, int *errp) goto decode_fail_free; } hdrsz = sframe_get_hdr_size (dhp); + + /* Validate that the FDE and FRE sub-sections described by the SFrame + header lie entirely within the SFrame buffer. The earlier call to + sframe_header_sanity_check_p has checked that sfh_fdeoff <= sfh_freoff. + The FDE sub-section holds sfh_num_fdes entries and precedes the FRE + sub-section, which is sfh_fre_len bytes long. The arithmetic below uses + subtraction and division so that it cannot itself overflow. */ + size_t fde_size = sizeof (sframe_func_desc_entry_v2); + if (sfp->sfp_version == SFRAME_VERSION_3) + fde_size = sizeof (sframe_func_desc_idx_v3); + if (hdrsz > sf_size + || dhp->sfh_freoff > sf_size - hdrsz + || dhp->sfh_fre_len > sf_size - hdrsz - dhp->sfh_freoff + || dhp->sfh_num_fdes > (dhp->sfh_freoff - dhp->sfh_fdeoff) / fde_size) + { + sframe_ret_set_errno (errp, SFRAME_ERR_BUF_INVAL); + goto decode_fail_free; + } + frame_buf += hdrsz; /* Handle the SFrame Function Descriptor Entry section. */