Page MenuHomeFreeBSD

link_elf: Uncapped dynamic-section walk (parse_dynamic)
Needs ReviewPublic

Authored by thebugfixers_pm.me on Wed, Jun 24, 9:41 AM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Jun 25, 7:13 PM
Unknown Object (File)
Thu, Jun 25, 4:23 PM
Subscribers

Details

Reviewers
None
Group Reviewers
Src Committers
Contributor Reviews (src)
Summary

There is no limit on how far this loop advances. If the PT_DYNAMIC segment is malformed and lacks a DT_NULL terminator within its bounds, the kernel scans forward indefinitely.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped