Conversation
Fixes potential OOB reads caused by malformed data. We might want to instead catch exceptions higher up the call stack, not sure. Fixes Vector35/binaryninja#1911
bpotchik
requested changes
Sep 24, 2026
bpotchik
left a comment
Member
There was a problem hiding this comment.
The exception fix prevents the crash, but it looks like there is a root cause here. There is an integer overflow that allows the out of bounds read. The bug is in two places, copied from the original FAT macho view.
- universaltransform.cpp
size_t requiredFatHeaderSize = fatHeader.nfat_arch * (isFat64 ? 32 : 20) + 8;
- fatmachoview.cpp
size_t expectSize = header.nfat_arch * ....
Just add a (size_t) to extend before the multipl on both: fatHeader.nfat_arch and header.nfat_arch
Also, yes I think catching higher up is the right call. Look in api/transform.cpp. Following the same patter in BinaryView::InitCallback(void* ctxt)
You could apply the pattern below to each of DecodeCallback, EncodeCallback, and CanDecodeCallback.
try {
....
catch (const std::exception& e)
{
LogError("Transform::DecodeWithContext failed: %s", e.what());
return false;
}
catch (...)
{
LogError("Transform::DecodeWithContext failed with unknown exception");
return false;
}
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes potential OOB reads (which in the binary reader cause exceptions) caused by malformed data. We might want to instead catch exceptions higher up the call stack, not sure. If we instead just want to guard every read with some bounds check or something im amenable to that, but honestly that might just bloat code up with potential bad guards 🤣 (and we typically only do that when we have a recoverable situation)
Fixes https://github.com/Vector35/binaryninja/issues/1911