Vector35 / Vector35/binaryninja-api

Type propagation fails to properly account for the size of a variable read.

Open
#2,182 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Binary Ninja Version: 2.2.2568-dev Personal, c88a4dc7
Platform: Windows

It seems that during lifting some information can be lost.
In attached archive there is two binaries:
First (test_no_cl_usage) doesn't include seta cl in x2 block and bn correctly shows that we will use struct1->field8 (last line):

изображение

also we can see correct output in HLIL:

изображение

but if we use seta cl in x2 block (test_cl_usage binary) we will get following picture:

изображение

in HLIL:

изображение

in this second case bn shows us that we are reading first field of structure and it seems a bit wrong..

bins.zip

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the two cases from bins.zip, comparing lifting and HLIL output for test_no_cl_usage and test_cl_usage. Trace type propagation around the x2 block and the variable read affected by seta cl; done means both binaries identify the intended struct1->field8 access consistently.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.