From 3415598cc7961daccadc62acb350c5b13c7b6140 Mon Sep 17 00:00:00 2001 From: Tomasz Leman Date: Wed, 7 Oct 2026 13:50:34 +0200 Subject: [PATCH] llext-manager: reject manifests with no module segments The existing overflow check only rejects a module entry array that runs past the image, so a manifest describing zero distinct text segments passes it and leaves n_mod == 0. The subsequent ctx->mod[n_mod - 1].n_mod store then writes immediately before the allocation. Bail out with -EINVAL once the modules have been counted and none were found. Found by clang-analyzer-security.ArrayBound. Assisted-by: Copilot:claude-opus-5 clang-tidy Signed-off-by: Tomasz Leman --- src/library_manager/llext_manager.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/src/library_manager/llext_manager.c b/src/library_manager/llext_manager.c index 75a2a7295482..022aba3c74e4 100644 --- a/src/library_manager/llext_manager.c +++ b/src/library_manager/llext_manager.c @@ -548,6 +548,16 @@ static int llext_manager_mod_init(struct lib_manager_mod_ctx *ctx, n_mod++; } + /* + * A manifest with no distinct module segments would leave n_mod == 0, + * making the ctx->mod[n_mod - 1] accesses below index out of bounds + */ + if (!n_mod) { + tr_err(&lib_manager_tr, "no module segments in %u entries", + desc->header.num_module_entries); + return -EINVAL; + } + /* * Loadable modules are loaded to DRAM once and never unloaded from it. * Context, related to them, is never freed