Re: [PATCH v2] hw/elf_ops: defend against weird elf headers

Philippe Mathieu-Daudé <[email protected]>
Newsgroups org.nongnu.qemu-devel
Message-ID <[email protected]>
On 12/8/26 10:14, Alex Bennée wrote:
> According to the ELF spec:
> 
>    PT_LOAD
> 
>    The array element specifies a loadable segment, described by
>    p_filesz and p_memsz. The bytes from the file are mapped to the
>    beginning of the memory segment. If the segment's memory
>    size (p_memsz) is larger than the file size (p_filesz), the
>    ``extra'' bytes are defined to hold the value 0 and to follow the
>    segment's initialized area. The file size may not be larger than the
>    memory size. Loadable segment entries in the program header table
>    appear in ascending order, sorted on the p_vaddr member.
> 
> which implies while both p_filesz and p_memsz can be zero we should
> never see a case where p_filesz is greater than the in memory size.
> Indeed it has been reported such a hand crafted ELF can blow up, for
> example during rom_reset():
> 
>    address_space_set(rom->as, rom->addr + rom->datasize, 0,
>                      rom->romsize - rom->datasize,
>                      MEMTXATTRS_UNSPECIFIED);
> 
> which could trigger and underflow leaving QEMU slowly filling a very
> large buffer.
> 
> Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/4056
> Signed-off-by: Alex Bennée <[email protected]>
> Cc: [email protected]
> 
> ---
> v2
>    - ret = ELF_LOAD_TOO_BIG
>    - tweak subject
> ---
>   include/hw/elf_ops.h.inc | 5 +++++
>   1 file changed, 5 insertions(+)

Reviewed-by: Philippe Mathieu-Daudé <[email protected]>

and queued via hw-misc tree, thanks.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.