Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 Jul 2026 14:11:23 +0000
From:      Jessica Clarke <jrtc27@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org
Subject:   git: 1e39a314d870 - main - link_elf: Make phdrs first page check actually fatal
Message-ID:  <6a6a0a0b.197de.5185cb8b@gitrepo.freebsd.org>

index | next in thread | raw e-mail

The branch main has been updated by jrtc27:

URL: https://cgit.FreeBSD.org/src/commit/?id=1e39a314d870e312f623199e146eda6bdbc293a3

commit 1e39a314d870e312f623199e146eda6bdbc293a3
Author:     Jessica Clarke <jrtc27@FreeBSD.org>
AuthorDate: 2026-07-29 14:09:42 +0000
Commit:     Jessica Clarke <jrtc27@FreeBSD.org>
CommitDate: 2026-07-29 14:09:42 +0000

    link_elf: Make phdrs first page check actually fatal
    
    Otherwise we'll print an error but carry on regardless, presumably
    destined to walk off the end of the mapping.
    
    Reported by:    thebugfixers@pm.me
    MFC after:      1 week
---
 sys/kern/link_elf.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/sys/kern/link_elf.c b/sys/kern/link_elf.c
index 613dfe0133d4..6ab5f4a39580 100644
--- a/sys/kern/link_elf.c
+++ b/sys/kern/link_elf.c
@@ -1086,8 +1086,11 @@ link_elf_load_file(linker_class_t cls, const char* filename,
 	 */
 	if (!((hdr->e_phentsize == sizeof(Elf_Phdr)) &&
 	      (hdr->e_phoff + hdr->e_phnum*sizeof(Elf_Phdr) <= PAGE_SIZE) &&
-	      (hdr->e_phoff + hdr->e_phnum*sizeof(Elf_Phdr) <= nbytes)))
+	      (hdr->e_phoff + hdr->e_phnum*sizeof(Elf_Phdr) <= nbytes))) {
 		link_elf_error(filename, "Unreadable program headers");
+		error = ENOEXEC;
+		goto out;
+	}
 
 	/*
 	 * Scan the program header entries, and save key information.


home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6a6a0a0b.197de.5185cb8b>