mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
Sanity check ELF notes descriptor size before reading it. This prevents
stack buffer overflows in case a dump contains invalid ELF notes.
Instead of reading a note's descriptor into a temporary buffer on stack,
read it directly into the buffer given to nt_read() but also provide
a maximum length of the given buffer to nt_read() in order to prevent
overflows.
This problem was found with valgrind and AFL fuzzing + ASAN.
AFL + ASAN findings:
[root@t83lp49 s390-tools]# ./zdump/zgetdump -iVVVVV ~/zgetdump-fuzzing/findings/crashes/id\:000008\,sig\:06\,src\:000007\,op\:arith8\,pos\:67\,val\:+3
TRACE: DFI initialization
DEBUG: DFI trying s390tape
DEBUG: DFI s390tape returned with rc -19
DEBUG: DFI trying devmem
DEBUG: DFI devmem returned with rc -19
DEBUG: DFI trying s390mv_ext
DEBUG: DFI s390mv_ext returned with rc -19
DEBUG: DFI trying s390mv
DEBUG: DFI s390mv returned with rc -19
DEBUG: DFI trying s390_ext
DEBUG: DFI S390 extended initialization
DEBUG: DFI s390_ext returned with rc -19
DEBUG: DFI trying s390
DEBUG: DFI S390 initialization
DEBUG: DFI s390 returned with rc -19
DEBUG: DFI trying lkcd
DEBUG: DFI lkcd returned with rc -19
DEBUG: DFI trying elf
DEBUG: DFI ELF initialization
DEBUG: DFI ELF e_phnum 11
DEBUG: DFI ELF p_type[0] 0x4
DEBUG: DFI ELF n_type 0x0
AddressSanitizer:DEADLYSIGNAL
=================================================================
==208548==ERROR: AddressSanitizer: stack-overflow on address 0x03ffef05d000 (pc 0x0000010051b0 bp 0x03fff107dc40 sp 0x03ffef05dac8 T0)
#0 0x10051b0 (/root/s390-tools/zdump/zgetdump+0x10051b0)
SUMMARY: AddressSanitizer: stack-overflow (/root/s390-tools/zdump/zgetdump+0x10051b0)
==208548==ABORTING
valgrind findings:
==56423== Source and destination overlap in memcpy(0x4a86d38, 0x4a875e0, 4096)
==56423== at 0x4839F86: memcpy (in /usr/lib/s390x-linux-gnu/valgrind/vgpreload_memcheck-s390x-linux.so)
==56423== by 0x114253: memcpy (string_fortified.h:34)
==56423== by 0x114253: nt_read (dfi_elf.c:95)
==56423== by 0x1145FF: nt_s390_prefix_read (dfi_elf.c:195)
==56423== by 0x1145FF: pt_notes_add (dfi_elf.c:259)
==56423== by 0x1145FF: dfi_elf_init (dfi_elf.c:326)
==56423== by 0x112A57: dfi_init (dfi.c:1212)
==56423== by 0x10D663: do_dump_info (zgetdump.c:127)
==56423== by 0x10D663: main (zgetdump.c:182)
==56423==
==56423== Invalid write of size 8
==56423== at 0x4839E28: memcpy (in /usr/lib/s390x-linux-gnu/valgrind/vgpreload_memcheck-s390x-linux.so)
==56423== by 0x114253: memcpy (string_fortified.h:34)
==56423== by 0x114253: nt_read (dfi_elf.c:95)
==56423== by 0x1145FF: nt_s390_prefix_read (dfi_elf.c:195)
==56423== by 0x1145FF: pt_notes_add (dfi_elf.c:259)
==56423== by 0x1145FF: dfi_elf_init (dfi_elf.c:326)
==56423== by 0x112A57: dfi_init (dfi.c:1212)
==56423== by 0x10D663: do_dump_info (zgetdump.c:127)
==56423== by 0x10D663: main (zgetdump.c:182)
==56423== Address 0x4a86ee0 is 0 bytes after a block of size 912 alloc'd
==56423== at 0x483675E: calloc (in /usr/lib/s390x-linux-gnu/valgrind/vgpreload_memcheck-s390x-linux.so)
==56423== by 0x10E71D: zg_alloc (zg.c:93)
==56423== by 0x114793: nt_prstatus_read (dfi_elf.c:123)
==56423== by 0x114793: pt_notes_add (dfi_elf.c:234)
==56423== by 0x114793: dfi_elf_init (dfi_elf.c:326)
==56423== by 0x112A57: dfi_init (dfi.c:1212)
==56423== by 0x10D663: do_dump_info (zgetdump.c:127)
==56423== by 0x10D663: main (zgetdump.c:182)
Signed-off-by: Alexander Egorenkov <egorenar@linux.ibm.com>
Suggested-by: Marc Hartmayer <mhartmay@linux.ibm.com>
Reported-by: Steffen Eiden <seiden@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>