Harden PE loader for malformed files - #8606
Merged
Merged
Conversation
plafosse
approved these changes
Oct 1, 2026
Round PointerToRawData down to a 0x200 boundary for page-aligned images instead of using FileAlignment. Preserve low-alignment mappings and distinguish zero raw pointers from nonzero pointers rounded to zero.
Round unaligned SizeOfRawData up to FileAlignment so code and data in the rounded range remain visible to segment mapping and RVA lookups. Use 64-bit arithmetic and clamp to virtual section and file bounds.
Preflight the COFF symbol table before importing any symbols. Validate table bounds, name offsets, terminators, and auxiliary record counts. Skip the table with one warning if validation or a limit fails. Add configurable limits of 100,000 records, 4 KiB per name, and 4 MiB of expanded name bytes, counting shared names once per reference. Setting a limit to -1 disables it.
Validate string-table offsets and bound section name reads using configurable per-name and aggregate limits. Fall back to header names with one warning when names are invalid or exceed a limit. Allow -1 to disable each limit. Always resolve names of eight bytes or fewer, including .reloc, to preserve relocation handling.
zznop
force-pushed
the
test_fix_pe_parsing_issues
branch
from
October 2, 2026 18:34
bd82d94 to
5a6196f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR hardens PE loading against reported malformed and adversarial files that can hide executable bytes or exhaust memory through repeated, oversized symbol names. It addresses the corresponding behaviors reported in these Ghidra issues:
f4fab0737— #9170: Incorrect raw section pointer alignmentAligns
PointerToRawDatadown to a fixed0x200boundary for page-aligned images, matching reported Windows loader behavior. Preserves low-alignment handling and distinguishes an original zero pointer from a nonzero pointer that rounds down to zero.dbe4536fe— #9171: Missing section data after raw-size roundingRounds
SizeOfRawDataup toFileAlignmentand tracks the aligned mapped extent separately from the displayed section size. This exposes code and data in the rounded portion, including whenVirtualSizeis zero or small. Segment mapping, RVA lookups, and symbol checks use consistent bounds, with EOF clipping and overflow-safe arithmetic.1e56c6555— #9169: Memory exhaustion through COFF symbol namesValidates optional PE COFF symbols before queuing them, enforcing independent limits on record count, individual name length, and total expanded name bytes. Shared strings are charged per reference. Invalid or excessive tables are skipped with one warning explaining that COFF-derived names and function hints may be unavailable.
bd82d94ad— #9169: Memory exhaustion through section namesBounds string-table section names individually and in aggregate. Invalid or excessive names fall back to their section-header names, with one warning. Names of eight bytes or fewer remain resolvable, preserving the existing
.relocfallback. Explicit numeric setting bounds also correct default-value display in Open with Options.All five limits are configurable;
-1disables the respective limit. PE base relocations remain independent of optional COFF symbol parsing, and directory-based relocation lookup remains independent of section names.The standalone COFF viewer is unchanged. COFF objects are normally compiler output, and their relocations depend on symbol-table information; applying the same symbol-skipping policy could break relocation resolution and analysis. Ordinary COFF objects are not independently executable, making them a lower-priority target for this particular hardening effort. PE malware can directly exploit pathological metadata and loader discrepancies to obstruct or mislead analysis.
The archive contains (4) PE files that are named after the reported GH issue and demonstrate each bug. These were used for testing and verification:
pe-issues.zip