Re: [PATCH v2] hw/elf_ops: defend against weird elf headers
Philippe Mathieu-Daudé <[email protected]>
| Newsgroups | org.nongnu.qemu-devel |
|---|---|
| Message-ID | <[email protected]> |
On 12/8/26 10:14, Alex Bennée wrote: > According to the ELF spec: > > PT_LOAD > > The array element specifies a loadable segment, described by > p_filesz and p_memsz. The bytes from the file are mapped to the > beginning of the memory segment. If the segment's memory > size (p_memsz) is larger than the file size (p_filesz), the > ``extra'' bytes are defined to hold the value 0 and to follow the > segment's initialized area. The file size may not be larger than the > memory size. Loadable segment entries in the program header table > appear in ascending order, sorted on the p_vaddr member. > > which implies while both p_filesz and p_memsz can be zero we should > never see a case where p_filesz is greater than the in memory size. > Indeed it has been reported such a hand crafted ELF can blow up, for > example during rom_reset(): > > address_space_set(rom->as, rom->addr + rom->datasize, 0, > rom->romsize - rom->datasize, > MEMTXATTRS_UNSPECIFIED); > > which could trigger and underflow leaving QEMU slowly filling a very > large buffer. > > Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/4056 > Signed-off-by: Alex Bennée <[email protected]> > Cc: [email protected] > > --- > v2 > - ret = ELF_LOAD_TOO_BIG > - tweak subject > --- > include/hw/elf_ops.h.inc | 5 +++++ > 1 file changed, 5 insertions(+) Reviewed-by: Philippe Mathieu-Daudé <[email protected]> and queued via hw-misc tree, thanks.