Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Sleigh segfaults on short inputs for JVM, NDS32 and SPARC

Đang mở
#293 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
48/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
cpp, python
Lĩnh vực
reverse-engineering

Hướng nghiên cứu

Bắt đầu bằng cách tái hiện ba lệnh gọi pypcode.Context.translate được cung cấp tại commit 559aacdc cho JVM, NDS32 và SPARC. Truy vết từng lỗi qua định nghĩa ngôn ngữ SLEIGH liên quan và phần xử lý đầu vào, đồng thời giữ chuỗi SPARC trong một lệnh gọi translate duy nhất. Hoàn tất khi cả ba đầu vào đều trả về mà không bị segfault và có thể được kiểm thử lại với patch.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS

Three Sleigh language definitions segfault on short byte sequences. They are
almost certainly three separate defects and can be split if that is easier to
triage — they are together here because they came out of one survey and share a
shape: a small input, no exception, the process gone.

All three reproduce on 559aacdc, which is master at the time of writing, and
each is a bare translate call with no other state.

1. JVM — tableswitch

pypcode.Context("JVM:BE:32:default").translate(
    bytes.fromhex("aa873b8e6f50b409"), 0x1001,
    max_instructions=99999, max_bytes=8,
    flags=pypcode.TranslateFlags.BB_TERMINATING)

0xaa is tableswitch; 0xab (lookupswitch) fails the same way. Eight bytes.

2. NDS32

pypcode.Context("NDS32:LE:32:default").translate(
    bytes.fromhex("26095d273add"), 0x1010,
    max_instructions=99999, max_bytes=6,
    flags=pypcode.TranslateFlags.BB_TERMINATING)

Six bytes.

3. SPARC

pypcode.Context("sparc:BE:32:default").translate(
    bytes.fromhex("1728394a5b6c7d8e9fb0c1d2b01e0019"), 0x14,
    max_instructions=99999, max_bytes=16,
    flags=pypcode.TranslateFlags.BB_TERMINATING)

This one needs the whole run in a single translate call — no individual word
in that sequence crashes on its own, which I checked.

How much weight to put on these

Less than on the PowerPC report I opened alongside this one, and I would rather
say so than oversell. That case is an ordinary vaddubm that a compiler emits,
and it corrupts the heap. These three are short sequences that do not correspond
to code any toolchain produces, so they are robustness findings rather than
something a user meets on real input.

They still seem worth having. A lifter is routinely pointed at binaries whose
provenance is unknown, and there the distinction between "valid code" and
"arbitrary bytes" does not hold — the caller cannot know which it has until
after the lift, and a segfault gives no opportunity to skip the block.

I have not attempted fixes and am not proposing any. Happy to retest against a
patch.

Ngôn ngữ chính
C++
Star
221
Fork
32
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của angr/pypcode

Tất cả issue của angr/pypcode

Issue tương tự

Thêm issue về C++

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.