From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 643323FFF8E for ; Thu, 9 Jul 2026 09:23:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783589022; cv=none; b=sW6agr1pLipdkRiJ2Gkfsa0Lv/zpPYn47ODCofEcXF8wod5VLgfbOgoxHO9IGln7Bwv/p+A++bhSrPJkq9FdgXNQlR5qX6v6TaMgGPX3fqdINgbwScsh85hUWWLQCOzzosVHbEhT/+tGjzbE46SQeeUu9RqOkm/rbrX44oV2oQo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783589022; c=relaxed/simple; bh=ugjTvsW7OPBUbId7o5OdCJlPpCtJimKjzsZpUdRwtbk=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=lA34yYzVQ0AMoo8aUo8lJ0IkzqGPJB0I4rCRfcVlBSBM/fG3bckAzIwk0DNeaFxaODuxSsxXJI5gNk8/KU9XJ+BoOoCcvD8emTL71ghHzD0ehe8TeABWNTDqrhtRKDJRTjNy5oIVlWsFrpQpvOGsKmatKg91QhoXsdD8gwWMLUQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=PkysJBkT; arc=none smtp.client-ip=209.85.221.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="PkysJBkT" Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-47362928f65so579733f8f.2 for ; Thu, 09 Jul 2026 02:23:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1783589020; x=1784193820; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=VTVYBQvEkKaNaBd+wNBZ0176hbApIof794YXIpaDqoc=; b=PkysJBkT/2ubq7Rs/W9EvuXitlJ1Wj/zurEHVRefIQpRw76rym0XbCKa56QUN42nfT KsximHxCU0sWa4rul/a5MhrADKlEt56rXwyWogJLNLgBzHS4dUt+OLXuz0Q+5MnClX+F kAytoKaIGE+UgwPg/zf7ZGzS2BvXxvNBZL6ZJYrWrXHBpESOUgzDgJKPFmAzvMgX7oYM X+TH0K1ZgtRG2ARjrWOTHD+MeCjsgiV6ZW3jcsacMynLUXRGkR2xtJq3OQOxe/wwmoJW kJrhDHGugkzJ6ZpwLErSu+JutNOklN08uio/N7v0Mb8/h4W/MJ3zdI+gSPZn/FK0CK1J Zigw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783589020; x=1784193820; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VTVYBQvEkKaNaBd+wNBZ0176hbApIof794YXIpaDqoc=; b=YBdVnoQG8LdqxjskfIV2Jh2upa+nJrIncuchMPERCIyjkTvHWrfD5StCnivcQB8yNs gBsZpzqdRSjxrGfOjb/+Cslo3SBe1nCFdcCyGdcGKS1uYgL7VD/JrVQ9jN+vioWcbZC4 NC+3vhfp17RlEWxVqPJkVjSOduLKVobKtvMLuQ/xIMVGe5r9IL0Z8tEq48ELP3X4RqW9 fn1CEtFVmzL8fMH2z/B7KO92hul43vHpLnOdkr2atarQYyW2gRNexrCazlwuyhz6HqPG 95ld6VdbXC0OEY/oAgmYkSIountWki1SJ7u4RzMlVaPWEXF/0Y68oO0crrjVgPg/QHJF no6Q== X-Forwarded-Encrypted: i=1; AHgh+RomrHBDs8noJX1kj6JZ/2YXQh17EXnqatOjpK015wvi3CJd3pr9cIDV/Kvkrir7R0UuHQ7huCgOubQgSPY=@vger.kernel.org X-Gm-Message-State: AOJu0YyhIq8VjprMOPHX0kzzhR+mk6HtoUKwjYI4Gyh8DIfLj1shuUVu RrMztBy2Mu24ADgHLjKphIuYUBEGY7Z/mzFMcnw9WNivJ5kRtQAMzHx6M5n7Ds93bZg= X-Gm-Gg: AfdE7cmxe5vZZU0X1it3r6DivXS13afnZarNiZG2SlAtD8CPVdmLwHlUmQoidKYvtWO ZCKhAgQeDcPQUnOslZDVWSlujsuWVV+FKO7R9QzvVi/jMxWRz3qTWoFke9KOZRAC2nKzYFu4Emc n6dh9Am66sMBlLUqPA34h0fvskqq8lVX/snoqPq3Raea5Pflrv1EEy97Lb2H6+jLBwMDHD14BNJ BnhjI9qwYC45xQe9aJKBor665rAdpB9um1N4h4/vjH5jq7pLejbtUneAR6/xl21psBZrdZp1tNV C11okszsmswlZ9iXshHTFpYGb5LQE/zOqgKSmbHdFkm2tY6TSUtSxsdUfDQcJj05Ye9moboOdVU 5AC0MQEnMs5yIw4f3RzFx4nCB0iESIm1OGWj/w4xIZqh9U+9n9infeeHNR9i+RDq08aleLoyRzQ iHpv+EC/LDixRPrZ5toV1lzF1F/qaeUQ4HNg== X-Received: by 2002:a05:6000:4709:b0:475:f0d1:eb69 with SMTP id ffacd0b85a97d-47df07c5accmr6852609f8f.54.1783589019599; Thu, 09 Jul 2026 02:23:39 -0700 (PDT) Received: from [192.168.42.79] (nat2.prg.suse.com. [195.250.132.146]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47a9e4d6e4csm47272862f8f.10.2026.07.09.02.23.38 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 09 Jul 2026 02:23:39 -0700 (PDT) Message-ID: <945d18e3-13b8-453b-89fd-05229ab37e96@suse.com> Date: Thu, 9 Jul 2026 11:23:38 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] module: validate string table section types To: =?UTF-8?Q?Thi=C3=A9baud_Weksteen?= Cc: Luis Chamberlain , Daniel Gomez , Sami Tolvanen , Aaron Tomlin , Siddharth Nayyar , linux-modules@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260708012107.1621513-1-tweek@google.com> <33fba1b5-d107-46cd-896f-bd2539a4a0b6@suse.com> Content-Language: en-US From: Petr Pavlu In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On 7/9/26 3:56 AM, Thiébaud Weksteen wrote: > On Thu, Jul 9, 2026 at 1:40 AM Petr Pavlu wrote: >> >> On 7/8/26 3:21 AM, Thiébaud Weksteen wrote: >>> In elf_validity_cache_sechdrs, section sizes and offsets are validated, >>> unless the section type is SHT_NULL or SHT_NOBITS. >>> >>> Later, elf_validity_cache_secstrings and elf_validity_cache_index_str >>> access the section name table (.shstrtab) and symbol string table >>> (.strtab) headers without first ensuring that their types are >>> SHT_STRTAB. If a section type is SHT_NULL or SHT_NOBITS, sh_offset has >>> not been validated and may reference out-of-bounds memory when >>> dereferenced in elf_validity_cache_secstrings or >>> elf_validity_cache_strtab. >>> >>> Validate that both string section headers are of type SHT_STRTAB before >>> caching them. >> >> The module loader should normally at least get through the signature and >> blacklist checks without crashing due to a corrupted module ELF file. >> Failing to validate the offset+size of .shstrtab means the module loader >> could crash before the blacklist check, so I believe it is useful to add >> this validation. >> >> How did you run into this issue? Was it observed in practice with the >> GNU or LLVM toolchain, or with some manually crafted module? > > Thanks for the review Petr. I found the issue while reading the code. > I am working on a separate commit that reuses some of the ELF parsing > logic (in a different subsystem, with simpler assertions). I was able > to confirm with a basic PoC (reusing a valid .ko and replacing the > type and offset of .shstrtab). Thanks for the explanation. The change looks ok to me. Reviewed-by: Petr Pavlu -- Petr