Skip to content

Fix out-of-bounds reads in asn1_parse_header ##crash - #26939

Merged
trufae merged 1 commit into
radareorg:masterfrom
Hsnmohd:asn1-header-bounds
Oct 10, 2026
Merged

trufae merged 1 commit into
radareorg:masterfrom
Hsnmohd:asn1-header-bounds

Conversation

@Hsnmohd

@Hsnmohd Hsnmohd commented Oct 9, 2026

Copy link
Copy Markdown
Contributor
  • Mark this if you consider it ready to merge
  • I've added tests (optional)
  • I wrote some lines in the book (optional)

Description

Out-of-bounds reads in the DER header parser

asn1_parse_header accepts a long-form length-of-length of length - 1, so the loop reading the length octets runs one byte past the buffer, and the BIT_STRING branch reads the unused-bits byte without checking the content pointer is still inside the buffer. Both are reachable from untrusted input through r_asn1_object_parse (Mach-O/PE code-signature and DER entitlement parsing) where the buffer is a tight allocation. test/unit/test_asn1.c aborts under ASAN at asn1.c:63 and asn1.c:88 without the fix.

Reject long-form lengths claiming more octets than the buffer holds and verify the bitstring content pointer stays inside the buffer before reading the unused-bits byte.
@trufae
trufae merged commit 49c7fec into radareorg:master Oct 10, 2026
50 checks passed
@trufae trufae added the CVE label Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants