From patchwork Thu Oct 16 01:41:12 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: DJ Delorie X-Patchwork-Id: 121941 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E61F8385842F for ; Thu, 16 Oct 2025 01:42:19 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E61F8385842F Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=E8AZKQS6 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTP id 878DA3858428 for ; Thu, 16 Oct 2025 01:41:17 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 878DA3858428 Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 878DA3858428 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1760578877; cv=none; b=GIxw5TCN9xsCqbNK+pS3n8TXv/UFYzfqs5/p/arLYTIQiWAQqOF2PHDgeYlYoTAa/lj/42M0TxaPrjZl1dDp7/TnUTrRr4IHUAdMf7jOF6DS68rlmZMj+7xusvX2ZTAXdzJpSqt3f/0zRsGBgv9n0H1mTuMjpc7G8Tf1/N6SkGc= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1760578877; c=relaxed/simple; bh=9p3R97GprqB8rIECDTwRl4K9jaSZWE5w2ZYW3L0jCME=; h=DKIM-Signature:Date:Message-Id:From:To:Subject; b=lI339Ydr6w7goUNmXPwW8+l7y3rwiLNXNblmpT0mDocqsu5ELmWfoqrv3LgLgrw+UOv+epzkgriWybyVguJFAv9DvF21j9juBdy1GrMAelXLWFf0P62IUulAiy6MGt9GDr1LvdkTLsUNuKEx1CbAeqZpEOrcPNwGGL70QiyJ/qw= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 878DA3858428 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1760578877; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:content-type:content-type; bh=qq0gznIYQCAPre5SRBrH+ZFQwwLHsl4w6SxpNqoqeBQ=; b=E8AZKQS6xJT/E9r3b5TInDa25+goZjqJkWBdc1VvYMElZ1UkfF7dLTJHCTdBT0AqksWSug vE900DEzF3LghJ/CnB7wEQSEPF5wOH+A3XS3iwogBaJk2GJg3kWE36Ff/O5MShjfcdwiow aGbqSBqDBVgOwb+HbtNsKEOfvMxJbRE= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-352-bjV-JdAyN9mEdEgsRXFHdw-1; Wed, 15 Oct 2025 21:41:15 -0400 X-MC-Unique: bjV-JdAyN9mEdEgsRXFHdw-1 X-Mimecast-MFC-AGG-ID: bjV-JdAyN9mEdEgsRXFHdw_1760578874 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 88DF118009C0 for ; Thu, 16 Oct 2025 01:41:14 +0000 (UTC) Received: from greed.delorie.com (unknown [10.22.90.104]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3E13F18004D4 for ; Thu, 16 Oct 2025 01:41:14 +0000 (UTC) Received: from greed.delorie.com.redhat.com (localhost [127.0.0.1]) by greed.delorie.com (8.16.1/8.16.1) with ESMTP id 59G1fClL2556626 for ; Wed, 15 Oct 2025 21:41:12 -0400 Date: Wed, 15 Oct 2025 21:41:12 -0400 Message-Id: From: DJ Delorie To: libc-alpha@sourceware.org Subject: sprof: check pread size and offset for overflow X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: HYZM85XuAOtRKb7lW65xfhnihjZdolyC1UHWtqqwp5E_1760578874 X-Mimecast-Originator: redhat.com content-type: text/plain; charset="US-ASCII"; x-default=true X-Spam-Status: No, score=-10.7 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED, SPF_HELO_PASS, SPF_NONE, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Add a bit of descriptive paranoia to the values we read from the ELF headers and use to access data. diff --git a/elf/sprof.c b/elf/sprof.c index c82c7c9db6..2267391679 100644 --- a/elf/sprof.c +++ b/elf/sprof.c @@ -410,6 +410,7 @@ load_shobj (const char *name) int fd; ElfW(Shdr) *shdr; size_t pagesize = getpagesize (); + struct stat st; /* Since we use dlopen() we must be prepared to work around the sometimes strange lookup rules for the shared objects. If we have a file foo.so @@ -550,14 +551,30 @@ load_shobj (const char *name) error (EXIT_FAILURE, errno, _("Reopening shared object `%s' failed"), map->l_name); + if (fstat (fd, &st) < 0) + error (EXIT_FAILURE, errno, _("stat(%s) failure"), map->l_name); + + /* We're depending on data that's being read from the file, so be a + bit paranoid here and make sure the requests are reasonable. + PREAD would have failed anyway, but this is more robust and + explains what happened better. */ +#define PCHECK(s,l) if ((s) < 0 || (l) < 0 \ + || ((s)+(l)) < 0 || ((s)+(l)) > st.st_size) \ + error (EXIT_FAILURE, ERANGE, \ + _("read outside of file extents %ld + %ld > %ld"), \ + (long int)(s), (long int)(l), st.st_size) + /* Map the section header. */ size_t size = ehdr->e_shnum * sizeof (ElfW(Shdr)); shdr = (ElfW(Shdr) *) alloca (size); + PCHECK (size, ehdr->e_shoff); if (pread (fd, shdr, size, ehdr->e_shoff) != size) error (EXIT_FAILURE, errno, _("reading of section headers failed")); /* Get the section header string table. */ char *shstrtab = (char *) alloca (shdr[ehdr->e_shstrndx].sh_size); + PCHECK (shdr[ehdr->e_shstrndx].sh_size, + shdr[ehdr->e_shstrndx].sh_offset); if (pread (fd, shstrtab, shdr[ehdr->e_shstrndx].sh_size, shdr[ehdr->e_shstrndx].sh_offset) != shdr[ehdr->e_shstrndx].sh_size) @@ -585,6 +602,7 @@ load_shobj (const char *name) size_t size = debuglink_entry->sh_size; char *debuginfo_fname = (char *) alloca (size + 1); debuginfo_fname[size] = '\0'; + PCHECK (size, debuglink_entry->sh_offset); if (pread (fd, debuginfo_fname, size, debuglink_entry->sh_offset) != size) { @@ -638,8 +656,13 @@ load_shobj (const char *name) if (fd2 != -1) { ElfW(Ehdr) ehdr2; + struct stat st; + + if (fstat (fd2, &st) < 0) + error (EXIT_FAILURE, errno, _("stat(%s) failure"), workbuf); /* Read the ELF header. */ + PCHECK (sizeof (ehdr2), 0); if (pread (fd2, &ehdr2, sizeof (ehdr2), 0) != sizeof (ehdr2)) error (EXIT_FAILURE, errno, _("reading of ELF header failed")); @@ -647,12 +670,15 @@ load_shobj (const char *name) /* Map the section header. */ size_t size = ehdr2.e_shnum * sizeof (ElfW(Shdr)); ElfW(Shdr) *shdr2 = (ElfW(Shdr) *) alloca (size); + PCHECK (size, ehdr2.e_shoff); if (pread (fd2, shdr2, size, ehdr2.e_shoff) != size) error (EXIT_FAILURE, errno, _("reading of section headers failed")); /* Get the section header string table. */ shstrtab = (char *) alloca (shdr2[ehdr2.e_shstrndx].sh_size); + PCHECK (shdr2[ehdr2.e_shstrndx].sh_size, + shdr2[ehdr2.e_shstrndx].sh_offset); if (pread (fd2, shstrtab, shdr2[ehdr2.e_shstrndx].sh_size, shdr2[ehdr2.e_shstrndx].sh_offset) != shdr2[ehdr2.e_shstrndx].sh_size)