PR 34342 SIGSEGV libctf/ctf-types.c:1603

Message ID akcLB6oWX_CHNrut@squeak.grove.modra.org
State New
Headers
Series PR 34342 SIGSEGV libctf/ctf-types.c:1603 |

Checks

Context Check Description
linaro-tcwg-bot/tcwg_binutils_build--master-aarch64 fail Patch failed to apply
linaro-tcwg-bot/tcwg_binutils_build--master-arm fail Patch failed to apply

Commit Message

Alan Modra July 3, 2026, 1:06 a.m. UTC
  Lots of analysis in the PR.

	* ctf-open.c (init_static_types_internal): Sanity check variable
	length record bytes against type section length.
	(upgrade_types_v1): Likewise.  Don't check unused "size" here.
  

Patch

diff --git a/libctf/ctf-open.c b/libctf/ctf-open.c
index 03992ef4c1a..584d502a29e 100644
--- a/libctf/ctf-open.c
+++ b/libctf/ctf-open.c
@@ -458,13 +458,14 @@  upgrade_types_v1 (ctf_dict_t *fp, ctf_header_t *cth)
       size = get_ctt_size_v1 (fp, (const ctf_type_t *) tp, NULL, &increment);
       vbytes = get_vbytes_v1 (fp, kind, size, vlen);
 
+      if (vbytes < 0
+	  || (uintptr_t) tend - (uintptr_t) tp < (size_t) increment + vbytes)
+	return ECTF_CORRUPT;
+
       get_ctt_size_v2_unconverted (fp, (const ctf_type_t *) tp, NULL,
 				   &v2increment);
       v2bytes = get_vbytes_v2 (fp, kind, size, vlen);
 
-      if ((vbytes < 0) || (size < 0))
-	return ECTF_CORRUPT;
-
       increase += v2increment - increment;	/* May be negative.  */
       increase += v2bytes - vbytes;
     }
@@ -748,7 +749,8 @@  init_static_types_internal (ctf_dict_t *fp, ctf_header_t *cth,
       (void) ctf_get_ctt_size (fp, tp, &size, &increment);
       vbytes = LCTF_VBYTES (fp, kind, size, vlen);
 
-      if (vbytes < 0)
+      if (vbytes < 0
+	  || (uintptr_t) tend - (uintptr_t) tp < (size_t) increment + vbytes)
 	return ECTF_CORRUPT;
 
       /* For forward declarations, ctt_type is the CTF_K_* kind for the tag,