Sleigh segfaults on short inputs for JVM, NDS32 and SPARC
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Lĩnh vực
- reverse-engineering
Hướng nghiên cứu
Bắt đầu bằng cách tái hiện ba lệnh gọi pypcode.Context.translate được cung cấp tại commit 559aacdc cho JVM, NDS32 và SPARC. Truy vết từng lỗi qua định nghĩa ngôn ngữ SLEIGH liên quan và phần xử lý đầu vào, đồng thời giữ chuỗi SPARC trong một lệnh gọi translate duy nhất. Hoàn tất khi cả ba đầu vào đều trả về mà không bị segfault và có thể được kiểm thử lại với patch.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS
Three Sleigh language definitions segfault on short byte sequences. They are
almost certainly three separate defects and can be split if that is easier to
triage — they are together here because they came out of one survey and share a
shape: a small input, no exception, the process gone.
All three reproduce on 559aacdc, which is master at the time of writing, and
each is a bare translate call with no other state.
1. JVM — tableswitch
pypcode.Context("JVM:BE:32:default").translate(
bytes.fromhex("aa873b8e6f50b409"), 0x1001,
max_instructions=99999, max_bytes=8,
flags=pypcode.TranslateFlags.BB_TERMINATING)
0xaa is tableswitch; 0xab (lookupswitch) fails the same way. Eight bytes.
2. NDS32
pypcode.Context("NDS32:LE:32:default").translate(
bytes.fromhex("26095d273add"), 0x1010,
max_instructions=99999, max_bytes=6,
flags=pypcode.TranslateFlags.BB_TERMINATING)
Six bytes.
3. SPARC
pypcode.Context("sparc:BE:32:default").translate(
bytes.fromhex("1728394a5b6c7d8e9fb0c1d2b01e0019"), 0x14,
max_instructions=99999, max_bytes=16,
flags=pypcode.TranslateFlags.BB_TERMINATING)
This one needs the whole run in a single translate call — no individual word
in that sequence crashes on its own, which I checked.
How much weight to put on these
Less than on the PowerPC report I opened alongside this one, and I would rather
say so than oversell. That case is an ordinary vaddubm that a compiler emits,
and it corrupts the heap. These three are short sequences that do not correspond
to code any toolchain produces, so they are robustness findings rather than
something a user meets on real input.
They still seem worth having. A lifter is routinely pointed at binaries whose
provenance is unknown, and there the distinction between "valid code" and
"arbitrary bytes" does not hold — the caller cannot know which it has until
after the lift, and a segfault gives no opportunity to skip the block.
I have not attempted fixes and am not proposing any. Happy to retest against a
patch.
- Ngôn ngữ chính
- C++
- Star
- 221
- Fork
- 32
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của angr/pypcode
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 28/100
-
Update to Ghidra 12.1.2Có thể làm lại được @mborgerson đã nhận 115 ngày trước và không có pull request nào đang mở. Đang mởenhancement
-
Build with freethreadingĐang mởenhancement
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Issue tương tự
-
Status: Awaiting triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
espressif/arduino-esp32#12984 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
torch_ops/logprob.cu does not compile with the serving container's nvcc (13.3.73); check_torch_ops.py cannot run as shippedCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 Dưới một giờ Mức phù hợp với người mới 72/100
ashhart/TensorFold#535 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày