Skip to content

WimHandler: backport 7-Zip 26.01 securId+1 bounds check - #261

Open
tonghuaroot wants to merge 1 commit into
p7zip-project:masterfrom
tonghuaroot:fix/wim-securid-oob-26.01
Open

WimHandler: backport 7-Zip 26.01 securId+1 bounds check#261
tonghuaroot wants to merge 1 commit into
p7zip-project:masterfrom
tonghuaroot:fix/wim-securid-oob-26.01

Conversation

@tonghuaroot

Copy link
Copy Markdown

Backports the CHandler::GetSecurity() bounds-check tightening landed in upstream 7-Zip 26.01 (released 2026-04-27).

What changed upstream

26.00 / p7zip bounded securityId against image.SecurOffsets.Size() but the very next two lines do:

```cpp
UInt32 offs = image.SecurOffsets[securityId];
UInt32 len = image.SecurOffsets[securityId + 1] - offs;
```

So the second indexing reads one element past the end of the SecurOffsets array whenever securityId == SecurOffsets.Size() - 1 (the last valid index).

26.01 changes the check to require both securId and securId + 1 to be below SecurOffsets.Size().

Impact

A crafted WIM image with a valid-looking-but-last security id produces a 4-byte out-of-bounds read of attacker-influenced metadata during GetProperty(kpidNtSecure). The read offset is consumed as offs and influences subsequent *data = buf + offs exposed via the IInArchive interface; downstream consumers may see attacker-influenced data.

Patch

Byte-for-byte matches upstream 26.01 source.

Disclosure

I am not a native English speaker. AI tooling was used to polish the prose in this PR description. The fix itself is a direct backport from upstream 7-Zip 26.01 source; no design choices were made beyond matching upstream verbatim.

Upstream 7-Zip 26.01 tightened CHandler::GetSecurity() so that both
securId and securId+1 are checked against image.SecurOffsets.Size()
before indexing.

p7zip's GetSecurity() bounds securityId against SecurOffsets.Size()
but the next two lines do:

  UInt32 offs = image.SecurOffsets[securityId];
  UInt32 len = image.SecurOffsets[securityId + 1] - offs;

so the second indexing reads one element past the end of the
SecurOffsets array whenever securityId == SecurOffsets.Size() - 1.
A crafted WIM image with a valid-looking-but-last security id
produces a 4-byte out-of-bounds read of attacker-influenced metadata
during GetProperty(kpidNtSecure).

Patch matches upstream 7-Zip 26.01 source.

Signed-off-by: tonghuaroot <tonghuaroot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant