Unnecessary `cs` segment override prefix (in Win32 flat mode) breaks jump table lifting

Open
#8,477 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
cpp

Research direction

Start by tracing x86 decoding of the 0x2e prefix and LLIL generation for the jmp [sib] sequence described in the issue. Check how Win32 flat-mode segment semantics are represented, then add a regression case for an equivalent instruction sequence if the test framework permits. Done means inert cs overrides no longer contribute cs.d or prevent jump-table lifting, while fs/gs behavior remains unchanged.

Written by the indexing model from the issue text.

Description

Version and Platform (required):

  • Binary Ninja Version: 5.3.9757 Personal (a99f2380)
  • OS: macOS
  • OS Version: 26.6.1
  • CPU Architecture: ARM64

Bug Description:
I have a Win32 user-mode binary from the 90s that, for whatever reason, contains a redundant 0x2e segment override prefix on a jmp [sib] opcode, where the SIB encodes a jump table which follows immediately afterwards (all absolute addresses, not position-independent).

Binary Ninja decides to turn this into an "Unresolved Indirect Control Flow" even though this segment override has no effect in Win32.

If I manually patch the segment override prefix into a nop in the hex editor view, this is able to work around the problem (in only that specific instance, of course).

Steps To Reproduce:
Please provide all steps required to reproduce the behavior:

  1. Load a binary that contains an unnecessary segment override as I've shown
  2. Look in the disassembly view and notice the large red ? question mark.
  3. Look in the LLIL view and see cs.d as part of the jump computation.
  4. Patch the 0x2e to 0x90 in the hex editor. Observe that everything works now.

Expected Behavior:
x86 segment overrides should be ignored on platforms where they are known to not do anything (which includes most modern userspace, for segments other than fs/gs)

Screenshots/Video Recording:
Screenshots of Binary Ninja seeing the segment override:

Image Image

Screenshot after manual patches in the hex editor

Image

Binary:
Unfortunately, I do not have permission to share the binary.

Additional Information:
N/A

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Vector35/binaryninja-api

All issues in Vector35/binaryninja-api

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.