[PATCH v2 2/8] fixdep: fix out-of-bounds read on a comment ending with a backslash
From: Leizhen Zhang
Date: Thu Oct 08 2026 - 12:42:15 EST
When skipping a comment, parse_dep_file() treats a backslash as escaping
the next character and skips it unconditionally. If the backslash is the
last character of the file, this steps over the terminating NUL and the
loop keeps reading beyond the end of the buffer:
$ printf 'foo.o: foo.c\n# x\\' > foo.d
$ touch foo.c
$ scripts/basic/fixdep foo.d foo.o cc
AddressSanitizer: heap-buffer-overflow ... in parse_dep_file
Only skip the character after the backslash if it is not the terminating
NUL.
Found by fuzzing fixdep with ASan/UBSan.
Fixes: bc6df812a152 ("fixdep: parse Makefile more correctly to handle comments etc.")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan
Signed-off-by: Leizhen Zhang <lzsx618@xxxxxxxxx>
---
v2:
- Use my real name in the From and Signed-off-by lines. No code
changes.
v1: https://lore.kernel.org/r/20261005104050.1786222-4-lzsx618@xxxxxxxxx
scripts/basic/fixdep.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/scripts/basic/fixdep.c b/scripts/basic/fixdep.c
index 54063d9804..9b57fe5554 100644
--- a/scripts/basic/fixdep.c
+++ b/scripts/basic/fixdep.c
@@ -280,7 +280,7 @@ static void parse_dep_file(char *p, const char *target)
* escaped newlines continue the comment across
* multiple lines.
*/
- if (*p == '\\')
+ if (*p == '\\' && *(p + 1) != '\0')
p++;
p++;
}
--
2.34.1