Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-36834 — 재현 가능한 CVE-2026-36834 개념 증명으로, LibRaw의 Panasonic RW2 디코더에서 발생하는 배열 경계를 벗어난 읽기(out-of-bounds array read)를 시연하며, 변이 스크립트와 샌나타이저 기반 크래시 재현을 포함합니다. | Kitploit
도구/GitHubGitHub/kpatsakis/cve-2026-36834
Memory ForensicsVulnerability AnalysisFuzzingBinary AnalysisPapers & ResearchLearning & Education
GitHubkpatsakis/cve-2026-36834

CVE-2026-36834

재현 가능한 CVE-2026-36834 개념 증명으로, LibRaw의 Panasonic RW2 디코더에서 발생하는 배열 경계를 벗어난 읽기(out-of-bounds array read)를 시연하며, 변이 스크립트와 샌나타이저 기반 크래시 재현을 포함합니다.

저장소 보기
103개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

요약

src/decoders/pana8.cpp에 배열 범위를 벗어난 읽기(out-of-bounds read)가 존재합니다. GetDBit() 함수는 Huffman 테이블 일치 항목이 없을 때 값 17을 반환할 수 있지만, huff_coeff[]는 17개의 요소(유효 인덱스 0-16)로만 선언되어 있습니다. 이로 인해 huff_coeff[17]에 접근하게 되어 UBSan과 AddressSanitizer로 확인된 정의되지 않은 동작(undefined behavior)이 발생합니다.

영향

LibRaw를 사용하는 이미지 편집기나 사진 관리 도구처럼 사용자가 제공한 RW2 파일을 처리하는 애플리케이션은 악성 파일을 여는 것만으로 충돌하거나 프로세스 메모리를 유출할 수 있습니다.

CWE: CWE-125 (Out-of-bounds Read), CWE-129 (Improper Validation of Array Index) CVSS v3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H (~6.5 Medium)

Git commit: 777f20ae21c611a78021bd051fbbf1e71eae78f2

영향을 받는 코드

File: src/decoders/pana8.cpp Function: pana8_param_t::DecodeC8()

근본 원인은 GetDBit()에 있습니다:

  uint32_t pana8_param_t::GetDBit(uint64_t a2)
  {
      for (int i = 0; i < 16; i++)
          if ((a2 & hufftable2[i]) == hufftable1[i])
              return i;
      return uint32_t((hufftable2[16] & a2) == hufftable1[16]) ^ 0x11u;
      // When comparison is false: returns 0 ^ 17 = 17
  }

그런 다음 반환 값은 범위 검사 없이 배열 인덱스로 직접 사용됩니다:

  huff_index = int(GetDBit(pixbits));          // can be 17
  int32_t v37 = (huff_coeff[huff_index] >> 24) // line 250: OOB
  uint32_t hc = huff_coeff[huff_index];        // line 251: OOB
  // ... and lines 254, 273

확인된 호출 체인(UBSan 출력) LibRaw::unpack() -> panasonicC8_load_raw() pana8.cpp:125 -> pana8_decode_loop() pana8.cpp:132 -> pana8_decode_strip() pana8.cpp:155 -> DecodeC8() pana8.cpp:250 <-- OOB triggered

트리거된 UBSan 오류: pana8.cpp:250 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:251 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:254 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:254 shift exponent -17 is negative pana8.cpp:273 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:303 left shift of negative value -1

재현

새니타이저로 LibRaw 빌드:

  ./configure CXXFLAGS="-fsanitize=address,undefined -g -O1" \
            LDFLAGS="-fsanitize=address,undefined"
  make -j$(nproc)

임의의 Panasonic RW2 파일에 대해 변이(mutator) 스크립트 실행:

  python3 mutate_rw2.py input.rw2 mutated_pana8.rw2
  ASAN_OPTIONS=halt_on_error=0:print_stats=1 ./bin/dcraw_emu -v mutated_pana8.rw2

패치

https://github.com/LibRaw/LibRaw/commit/02da167e0f819a37dbb7d714e87c5b40df6c5917

도구 다운로드