[PATCH 3/9] fixdep: fix out-of-bounds read on a comment ending with a backslash
From: lzhan011
Date: Mon Oct 05 2026 - 06:47:04 EST
From: lzhan011 <zhangleizhen645@xxxxxxxxx>
When skipping a comment, parse_dep_file() treats a backslash as escaping
the next character and skips it unconditionally. If the backslash is the
last character of the file, this steps over the terminating NUL and the
loop keeps reading beyond the end of the buffer:
$ printf 'foo.o: foo.c\n# x\\' > foo.d
$ touch foo.c
$ scripts/basic/fixdep foo.d foo.o cc
AddressSanitizer: heap-buffer-overflow ... in parse_dep_file
Only skip the character after the backslash if it is not the terminating
NUL.
Found by fuzzing fixdep with ASan/UBSan.
Fixes: bc6df812a152 ("fixdep: parse Makefile more correctly to handle comments etc.")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan
Signed-off-by: lzhan011 <zhangleizhen645@xxxxxxxxx>
---
scripts/basic/fixdep.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/scripts/basic/fixdep.c b/scripts/basic/fixdep.c
index 54063d980..9b57fe555 100644
--- a/scripts/basic/fixdep.c
+++ b/scripts/basic/fixdep.c
@@ -280,7 +280,7 @@ static void parse_dep_file(char *p, const char *target)
* escaped newlines continue the comment across
* multiple lines.
*/
- if (*p == '\\')
+ if (*p == '\\' && *(p + 1) != '\0')
p++;
p++;
}
--
2.34.1