[PATCH v2 7/8] sorttable: avoid pointer arithmetic overflow when locating sort_needed
From: Leizhen Zhang
Date: Thu Oct 08 2026 - 12:44:08 EST
The location of the main_extable_sort_needed variable is computed as
(void *)ehdr + shdr_offset(sec) + sym_value(sym) - shdr_addr(sec)
which first adds the symbol's virtual address (e.g. 0xffffffff8...) to
the pointer and only then subtracts the section address. The
intermediate pointer overflows, which is undefined behaviour and is
reported by UBSan.
Subtract the section address from the symbol value first.
Fixes: a79f248b9b30 ("scripts: Add sortextable to sort the kernel's exception table.")
Assisted-by: Claude:claude-opus-5-5 UBSan
Signed-off-by: Leizhen Zhang <lzsx618@xxxxxxxxx>
---
v2:
- Use my real name in the From and Signed-off-by lines. No code
changes.
v1: https://lore.kernel.org/r/20261005104050.1786222-9-lzsx618@xxxxxxxxx
scripts/sorttable.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/scripts/sorttable.c b/scripts/sorttable.c
index 88e49a5c42..0425e00c49 100644
--- a/scripts/sorttable.c
+++ b/scripts/sorttable.c
@@ -788,7 +788,7 @@ static int do_sort(Elf_Ehdr *ehdr,
sort_needed_sec = get_index(shdr_start, shentsize, sort_need_index);
sort_needed_loc = (void *)ehdr +
shdr_offset(sort_needed_sec) +
- sym_value(sort_needed_sym) - shdr_addr(sort_needed_sec);
+ (sym_value(sort_needed_sym) - shdr_addr(sort_needed_sec));
/* extable has been sorted, clear the flag */
elf_parser.w(0, sort_needed_loc);
--
2.34.1