This patch fixes a heap out-of-bounds read in print_cu_index_section()
(src/readelf.c:12363).

The products section_count * 4 and unit_count * section_count *
off_bytes are computed in 32 bits and wrap, defeating the sanity
checks; the loop then indexes with 64-bit values, reading up to 4 GiB
out of bounds. ASan aborts on the PoC.

The patch widens the arithmetic to size_t and adds a SIZE_MAX /
off_bytes / unit_count guard. Verified with an ASan build: the PoC
crashes before the patch and is clean after.

Patch is attached as elfutils-fix.patch.

AI tool use disclosure: AI was used in part for code audit and patch drafting.

Attachment: elfutils-fix.patch
Description: Binary data

Reply via email to