Skip to content

pe.relocation.RelocationData.parse_with_opts - Possible out of bound#468

Closed
BinFlip wants to merge 2 commits intom4b:masterfrom
BinFlip:pe.relocation.parse_with_opts_crash
Closed

pe.relocation.RelocationData.parse_with_opts - Possible out of bound#468
BinFlip wants to merge 2 commits intom4b:masterfrom
BinFlip:pe.relocation.parse_with_opts_crash

Conversation

@BinFlip
Copy link
Contributor

@BinFlip BinFlip commented Jun 4, 2025

Found another possible out of bound memory access while fuzzing my project that uses goblin

crash-6b996e5a1942c4b4d0156dac6616e087aff8f761.zip

@kkent030315
Copy link
Contributor

I am pretty sure this PR is duplicate of #465. By the way thank you for the heads up :D

@BinFlip
Copy link
Contributor Author

BinFlip commented Jun 9, 2025

Ah I must have missed that when looking through the PRs! In that case we can close #468 as duplicate. Do you have any estimate on when #465 will be merged?

@m4b
Copy link
Owner

m4b commented Jun 14, 2025

Ah I must have missed that when looking through the PRs! In that case we can close #468 as duplicate. Do you have any estimate on when #465 will be merged?

I'll review it this weekend, hopefully get it merged, thanks for your patience!

@m4b
Copy link
Owner

m4b commented Jun 14, 2025

I could also just merge this for time being since it's very simple 🤷

@BinFlip
Copy link
Contributor Author

BinFlip commented Jun 14, 2025

Thank you! I'm okay with waiting a bit longer, and I'd rather have the original finder and author credited

@BinFlip BinFlip closed this Jun 14, 2025
@BinFlip BinFlip deleted the pe.relocation.parse_with_opts_crash branch June 14, 2025 13:15
@BinFlip BinFlip restored the pe.relocation.parse_with_opts_crash branch June 14, 2025 13:17
@x0rb3l
Copy link
Contributor

x0rb3l commented Jul 25, 2025

Same root cause found in load_config.rs #481

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants