Skip to content

Fix heap out-of-bounds reads in the Android binary XML decoder ##crash - #26931

Merged
trufae merged 1 commit into
radareorg:masterfrom
Hsnmohd:axml-chunk-bounds
Oct 9, 2026
Merged

trufae merged 1 commit into
radareorg:masterfrom
Hsnmohd:axml-chunk-bounds

Conversation

@Hsnmohd

@Hsnmohd Hsnmohd commented Oct 8, 2026

Copy link
Copy Markdown
Contributor
  • Mark this if you consider it ready to merge
  • I've added tests (optional)
  • I wrote some lines in the book (optional)

Description

bound the string pool and element reads in r_axml_decode by the size each chunk was allocated with, since string_count, the element name index and attribute_count all come straight from the file and pFA on a crafted AndroidManifest walks off both chunks.

string_lookup indexed pool->offsets[] up to the file supplied pool->string_count, while pool is only header.size bytes. an 80 byte binary XML with a 32 byte string pool chunk declaring string_count=0x100000:

==80321==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x603000001ef7
READ of size 1 at 0x603000001ef7 thread T0
    #0 string_lookup axml.c:110
    #1 dump_element axml.c:232
    #2 r_axml_decode axml.c:410

0x603000001ef7 is located 7 bytes after 32-byte region [0x603000001ed0,0x603000001ef0)
allocated by thread T0 here:
    #1 r_axml_decode axml.c:382

a pool chunk shorter than 20 bytes gets its header fields read out of bounds the same way, a 16 byte start element chunk reads attribute_count past its own allocation, and the old attribute bound (count * sizeof (attribute_t) > element_size) ignored the 28 byte node header so attributes[] ran off the chunk too. the chunk size fields also stopped being truncated to ut16, otherwise a string pool larger than 64KB would now be rejected instead of misparsed.

test/unit/test_axml.c builds those four chunks plus a valid manifest in memory, so it aborts under the asan unit test job without the fix and passes with it.

@trufae
trufae merged commit e70f71a into radareorg:master Oct 9, 2026
50 checks passed
@trufae

trufae commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

I can confirm the four crashes with asan. The patch looks good! Thanks!

@Hsnmohd

Hsnmohd commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

appreciate the quick merge, and good to hear the asan repro lined up on your side too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants