From nobody Mon Sep 14 21:55:45 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hkJqj4X4bz6s3MK for ; Mon, 14 Sep 2026 21:55:45 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hkJqj3QWZz4sZP for ; Mon, 14 Sep 2026 21:55:45 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789422945; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=pv5VtDrEQ+UpPY0R8u0u+zVbJNAoAQw3VngLdVelCqQ=; b=HW0f/PgXR0SHGHNJqpZH+QmIDh4P4JGLzFN643qsKGbLZfDlAxJ6Ppv3JWT9b0dnf1XyR6 exqZVqa4Bj0WNNFWGcB92jE+o+mxAQChJ66hTKwWs4rdlrbxpoVb9HeReBA9ROzzWzQDuU lHkYIz2XYwX6uXhEoSpK+IHhlCPDbphhK1n+/k1dGAUZupFRvfcRrpxhlzfuXB/ejJS1cm 582fs0gjJUUPphwrALrBFhfzhKIWUlzmcK2AmTPqUlp9wljWkttQ9SbMBbhGoZ/9QbIyTU bhwsW2n0JiphBnO6lq3KLodNTUpxXi2v6pc/u7zTI7tWmLc7TBFCiwvWZ7sPCg== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1789422945; b=fZMGUfKeZwqf4PYUU14WSJan1gVgx6DuegFywyNvzIKzkZA00+5lPE9WM/c6LLV14Ctwnt TKPMdQCNHbPkx4uIY3lk+zf7Na8ZTSjz1913865pkWjq8Me4Xde8sBUdDKE+aFhDTplkHm IPTqRx2dDqYp5JyZX3+gvZhCOxKU02GettUsKJPYK0Dfg8SuaR+0OLRNw3Asd1sM1Aezys VkuPK6ta3C28l2H3A9wBc9UPLmGqbv9q7B98wKLVCGEDkVpX6oJ9OZPkam69bfaltCrPl0 VQxucvH1gv58VJyQCaBPm6cwGzFqn1vrpN7l1XHEw2CEhhC+nhT5HFVk9UPZxw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789422945; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=pv5VtDrEQ+UpPY0R8u0u+zVbJNAoAQw3VngLdVelCqQ=; b=BTZCXwjp0HJVubLnTZCRGZuS99K99DU3EUR4rHlqWoI0Z1ReKBlrJNvOaKDaE9REQTlZZd zil6aWFp+YSxXyTPLzWb7llSUyKywA3MDhlXwNR3oHlb4Rh2x3ujrkBFEFrhy8e4T7HYk0 JavdzWaOnR86eSR+/LzUH6AyL1OR0FqDSpEsIyf6h5k/1hFHT0yz1rTT4/sH9SawZD5+XN 9tmCOzEUH+sTvLMB2dA6EbsAaC25zUFGrPBuNjGjVeAOH4zSg4Eds6sGqqXeuEIIEB1sjb zDl8NLyWKtnZuEO+UZ2hRfbLZFop+YT+P3ZHRrihXLYoKukrr06Eh7lw4lUBfg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hkJqj25lVzWxk for ; Mon, 14 Sep 2026 21:55:45 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3abde by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 14 Sep 2026 21:55:45 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Konstantin Belousov Subject: git: fa848d4d0c03 - main - rtld: more caution when parsing in digest_notes() List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: fa848d4d0c0371cdbf39265b6528f4c61bc02c7d Auto-Submitted: auto-generated Date: Mon, 14 Sep 2026 21:55:45 +0000 Message-Id: <6aa86d61.3abde.109a8e10@gitrepo.freebsd.org> The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/src/commit/?id=fa848d4d0c0371cdbf39265b6528f4c61bc02c7d commit fa848d4d0c0371cdbf39265b6528f4c61bc02c7d Author: Konstantin Belousov AuthorDate: 2026-09-13 10:10:37 +0000 Commit: Konstantin Belousov CommitDate: 2026-09-14 21:55:01 +0000 rtld: more caution when parsing in digest_notes() Incorrect ELF might have PT_NOTE slightly larger than the needed to contain all notes, and the PT_NOTE size could be larger than one page. Then rtld mmaps just the notes bytes to parse. After the last note, we iterate past the mapped region trying to read the Elf_Note header. This was found in wild. Require full elf note to fit into the [start_note, end_note) region to continue the parsing. Check it in stages, first verifying the Elf_Note header structure fits, to be able to read the name and data length. After that, check the whole note against limit. Reported and tested by: makc Reviewed by: emaste Sponsored by: The FreeBSD Foundation MFC after: 1 week Differential revision: https://reviews.freebsd.org/D59635 --- libexec/rtld-elf/rtld.c | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/libexec/rtld-elf/rtld.c b/libexec/rtld-elf/rtld.c index 469488d094f9..850e017a404d 100644 --- a/libexec/rtld-elf/rtld.c +++ b/libexec/rtld-elf/rtld.c @@ -1785,14 +1785,19 @@ digest_phdr(const Elf_Phdr *phdr, int phnum, caddr_t entry, const char *path) void digest_notes(Obj_Entry *obj, Elf_Addr note_start, Elf_Addr note_end) { - const Elf_Note *note; + const Elf_Note *note, *next_note; const char *note_name; uintptr_t p; - for (note = (const Elf_Note *)note_start; (Elf_Addr)note < note_end; - note = (const Elf_Note *)((const char *)(note + 1) + - roundup2(note->n_namesz, sizeof(Elf32_Addr)) + - roundup2(note->n_descsz, sizeof(Elf32_Addr)))) { + for (note = (const Elf_Note *)note_start;; note = next_note) { + if ((Elf_Addr)note + sizeof(Elf_Note) > note_end) + break; + next_note = (const Elf_Note *)((const char *)(note + 1) + + roundup2(note->n_namesz, sizeof(Elf32_Addr)) + + roundup2(note->n_descsz, sizeof(Elf32_Addr))); + if ((Elf_Addr)next_note > note_end) + break; + if (arch_digest_note(obj, note)) continue;