
재현 가능한 CVE-2026-36834 개념 증명으로, LibRaw의 Panasonic RW2 디코더에서 발생하는 배열 경계를 벗어난 읽기(out-of-bounds array read)를 시연하며, 변이 스크립트와 샌나타이저 기반 크래시 재현을 포함합니다.
src/decoders/pana8.cpp에 배열 범위를 벗어난 읽기(out-of-bounds read)가 존재합니다. GetDBit() 함수는 Huffman 테이블 일치 항목이 없을 때 값 17을 반환할 수 있지만, huff_coeff[]는 17개의 요소(유효 인덱스 0-16)로만 선언되어 있습니다. 이로 인해 huff_coeff[17]에 접근하게 되어 UBSan과 AddressSanitizer로 확인된 정의되지 않은 동작(undefined behavior)이 발생합니다.
LibRaw를 사용하는 이미지 편집기나 사진 관리 도구처럼 사용자가 제공한 RW2 파일을 처리하는 애플리케이션은 악성 파일을 여는 것만으로 충돌하거나 프로세스 메모리를 유출할 수 있습니다.
CWE: CWE-125 (Out-of-bounds Read), CWE-129 (Improper Validation of Array Index) CVSS v3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H (~6.5 Medium)
Git commit: 777f20ae21c611a78021bd051fbbf1e71eae78f2
File: src/decoders/pana8.cpp Function: pana8_param_t::DecodeC8()
근본 원인은 GetDBit()에 있습니다:
uint32_t pana8_param_t::GetDBit(uint64_t a2)
{
for (int i = 0; i < 16; i++)
if ((a2 & hufftable2[i]) == hufftable1[i])
return i;
return uint32_t((hufftable2[16] & a2) == hufftable1[16]) ^ 0x11u;
// When comparison is false: returns 0 ^ 17 = 17
}
그런 다음 반환 값은 범위 검사 없이 배열 인덱스로 직접 사용됩니다:
huff_index = int(GetDBit(pixbits)); // can be 17
int32_t v37 = (huff_coeff[huff_index] >> 24) // line 250: OOB
uint32_t hc = huff_coeff[huff_index]; // line 251: OOB
// ... and lines 254, 273
확인된 호출 체인(UBSan 출력) LibRaw::unpack() -> panasonicC8_load_raw() pana8.cpp:125 -> pana8_decode_loop() pana8.cpp:132 -> pana8_decode_strip() pana8.cpp:155 -> DecodeC8() pana8.cpp:250 <-- OOB triggered
트리거된 UBSan 오류: pana8.cpp:250 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:251 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:254 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:254 shift exponent -17 is negative pana8.cpp:273 index 17 out of bounds for type 'unsigned int [17]' pana8.cpp:303 left shift of negative value -1
새니타이저로 LibRaw 빌드:
./configure CXXFLAGS="-fsanitize=address,undefined -g -O1" \
LDFLAGS="-fsanitize=address,undefined"
make -j$(nproc)
임의의 Panasonic RW2 파일에 대해 변이(mutator) 스크립트 실행:
python3 mutate_rw2.py input.rw2 mutated_pana8.rw2
ASAN_OPTIONS=halt_on_error=0:print_stats=1 ./bin/dcraw_emu -v mutated_pana8.rw2
https://github.com/LibRaw/LibRaw/commit/02da167e0f819a37dbb7d714e87c5b40df6c5917