|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH 2/2] tools/symbols: leave room for the type byte and NUL when expanding tokens
Symbol records in the compressed stream are stored as [type][name]: the
symbol type byte is part of the compressed data ("include the type field
in the symbol name, so that it gets compressed together"). A compression
token can therefore expand to a full record, i.e. the type byte followed
by an entire legal 127-byte name: 1 + 127 = 128 bytes.
write_src() expands every token into a local buffer to emit the token
dictionary, and expand_symbol() appends a terminating NUL to the result.
The buffer was char buf[KSYM_NAME_LEN + 1] (128 bytes) -- room for the
type and name, but not for the NUL. A token covering a full record
overruns it by one byte.
Allocate KSYM_NAME_LEN + 2 bytes, so the buffer holds type + name + NUL
(1 + 127 + 1 = 129 bytes). The previous patch limits names to
KSYM_NAME_LEN bytes, so no token can be longer than this.
This is a host generator overflow that occurs even when every symbol
name satisfies the runtime limit. It needs a token that covers a whole
record, which only happens with a very small symbol table. Real symbol
tables do not trigger it, and Xen itself is not affected.
A host reproducer supplies 64 identical 127-byte names of type T at
successive addresses. The original generator reports:
SUMMARY: AddressSanitizer: stack-buffer-overflow xen/tools/symbols.c:307 in
expand_symbol
The overflowing object is reported as:
[1184, 1312) 'buf' (line 341) <== Memory access at offset 1312 overflows this
variable
The fixed generator processes the same input successfully under
ASan/UBSan with no diagnostics.
Assisted-by: Codex:GPT-6.1
Assisted-by: Copilot:claude-sonnet-5.5 # host and x86 build tests
Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
---
xen/tools/symbols.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/xen/tools/symbols.c b/xen/tools/symbols.c
index e15273a8ad..f6319d6259 100644
--- a/xen/tools/symbols.c
+++ b/xen/tools/symbols.c
@@ -338,7 +338,8 @@ static void write_src(void)
unsigned int i, k, off, ends;
unsigned int best_idx[256];
unsigned int *markers;
- char buf[KSYM_NAME_LEN+1];
+ /* Type byte, longest name and terminating NUL. */
+ char buf[KSYM_NAME_LEN + 2];
if (map_only) {
for (i = 0; i < table_cnt; i++)
--
2.53.0
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |