[PATCH 8/9] sorttable: avoid pointer arithmetic overflow when locating sort_needed
From: lzhan011
Date: Mon Oct 05 2026 - 06:47:49 EST
From: lzhan011 <zhangleizhen645@xxxxxxxxx>
The location of the main_extable_sort_needed variable is computed as
(void *)ehdr + shdr_offset(sec) + sym_value(sym) - shdr_addr(sec)
which first adds the symbol's virtual address (e.g. 0xffffffff8...) to
the pointer and only then subtracts the section address. The
intermediate pointer overflows, which is undefined behaviour and is
reported by UBSan.
Subtract the section address from the symbol value first.
Fixes: a79f248b9b30 ("scripts: Add sortextable to sort the kernel's exception table.")
Assisted-by: Claude:claude-opus-5-5 UBSan
Signed-off-by: lzhan011 <zhangleizhen645@xxxxxxxxx>
---
scripts/sorttable.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/scripts/sorttable.c b/scripts/sorttable.c
index 88e49a5c4..0425e00c4 100644
--- a/scripts/sorttable.c
+++ b/scripts/sorttable.c
@@ -788,7 +788,7 @@ static int do_sort(Elf_Ehdr *ehdr,
sort_needed_sec = get_index(shdr_start, shentsize, sort_need_index);
sort_needed_loc = (void *)ehdr +
shdr_offset(sort_needed_sec) +
- sym_value(sort_needed_sym) - shdr_addr(sort_needed_sec);
+ (sym_value(sort_needed_sym) - shdr_addr(sort_needed_sec));
/* extable has been sorted, clear the flag */
elf_parser.w(0, sort_needed_loc);
--
2.34.1