From: Mark Wielaard Date: Wed, 12 Feb 2025 23:02:32 +0000 (+0100) Subject: libelf: Handle elf_strptr on section without any data X-Git-Tag: elfutils-0.193~42 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=b16f441cca0a4841050e3215a9f120a6d8aea918;p=thirdparty%2Felfutils.git libelf: Handle elf_strptr on section without any data In the unlikely situation that elf_strptr was called on a section with sh_size already set, but that doesn't have any data yet we could crash trying to verify the string to return. This could happen for example when a new section was created with elf_newscn, but no data having been added yet. * libelf/elf_strptr.c (elf_strptr): Check strscn->rawdata_base is not NULL. https://sourceware.org/bugzilla/show_bug.cgi?id=32672 Signed-off-by: Mark Wielaard --- diff --git a/libelf/elf_strptr.c b/libelf/elf_strptr.c index c5a94f82..7be7f5e8 100644 --- a/libelf/elf_strptr.c +++ b/libelf/elf_strptr.c @@ -1,5 +1,6 @@ /* Return string pointer from string section. Copyright (C) 1998-2002, 2004, 2008, 2009, 2015 Red Hat, Inc. + Copyright (C) 2025 Mark J. Wielaard This file is part of elfutils. Contributed by Ulrich Drepper , 1998. @@ -183,9 +184,12 @@ elf_strptr (Elf *elf, size_t idx, size_t offset) // initialized yet (when data_read is zero). So we cannot just // look at the rawdata.d.d_size. - /* Make sure the string is NUL terminated. Start from the end, - which very likely is a NUL char. */ - if (likely (validate_str (strscn->rawdata_base, offset, sh_size))) + /* First check there actually is any data. This could be a new + section which hasn't had any data set yet. Then make sure + the string is at a valid offset and NUL terminated. */ + if (unlikely (strscn->rawdata_base == NULL)) + __libelf_seterrno (ELF_E_INVALID_SECTION); + else if (likely (validate_str (strscn->rawdata_base, offset, sh_size))) result = &strscn->rawdata_base[offset]; else __libelf_seterrno (ELF_E_INVALID_INDEX);