[PATCH kexec-tools] util_lib/elf_info: bound VMCOREINFO string comparisons

Simon Horman horms at kernel.org
Mon Oct 5 02:07:27 PDT 2026


On Fri, Sep 11, 2026 at 10:23:51AM -0400, Serapheim Dimitropoulos wrote:
> From: Serapheim Dimitropoulos <sdimitropoulos at coreweave.com>
> 
> scan_vmcoreinfo() terminates each VMCOREINFO line before matching
> known field prefixes. Most fields nevertheless use memcmp() with the
> full prefix length, so a short line near the end of the note can make
> the comparison read beyond the allocated note buffer. AddressSanitizer
> reports a 24-byte read immediately past the allocation in this case.
> 
> Use strncmp() for the terminated VMCOREINFO lines and in the arm64
> VMCOREINFO hook. Check the ELF note name length before comparing it,
> and ignore an empty VMCOREINFO descriptor.
> 
> Fixes: f4ce0706d957 ("util_lib: Add functionality to read elf notes")
> Signed-off-by: Serapheim Dimitropoulos <sdimitropoulos at coreweave.com>
> ---
> AddressSanitizer found this while running vmcore-dmesg against a minimal
> arm64 ELF core. A two-byte VMCOREINFO descriptor containing "X\n" makes
> scan_vmcoreinfo() request a 24-byte comparison from the final four bytes
> of the 28-byte PT_NOTE allocation. ASan reports the read at
> scan_vmcoreinfo(), with the allocation originating in scan_notes().
> 
> Before this patch the reproducer aborts with:
> 
>   ERROR: AddressSanitizer: heap-buffer-overflow
>   READ of size 24
>   0 bytes after 28-byte region
> 
> After the patch, the reproducer completes without a sanitizer report.
> Empty VMCOREINFO descriptors and undersized note names were also tested.
> A valid synthetic legacy vmcore exits successfully and produces the
> expected output byte-for-byte.
> 
> The patch was tested on arm64 Ubuntu 24.04 with AddressSanitizer and with
> make distcheck.

Thanks, applied.
Sorry for the delay.

- util_lib/elf_info: bound VMCOREINFO string comparisons
  https://git.kernel.org/pub/scm/utils/kernel/kexec/kexec-tools.git/commit/?id=0fd0d8e9ea97



More information about the kexec mailing list