Missing Phi Function in MLIL

Open
#4,546 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
cpp

Research direction

Open sacsess.tar.gz at CVTUTF8Scraper::Write (0x140003750) and inspect the MLIL blocks where rdx_2 is used, focusing on the block at address 93. Compare its definitions with the existing dwSize#4 phi; done means rdx_2#4 is defined by a phi combining rdx_2#2 and rdx_2#3.

Written by the indexing model from the issue text.

Description

Component: Core Core: MLIL Impact: Medium

Version and Platform (required):

  • Binary Ninja Version: 3.5.4425-dev
  • OS: Arch Linux
  • OS Version: -
  • CPU Architecture: x64

Bug Description:
Take a look at the following CFG:
Screenshot_20230804_111137

rdx_2#2 and rdx_2#3 are assigned in the upper blocks which lead into the block at address 93.
In that block rdx_2#4 is used, but not defined.
It should be defined by a phi function in the form of rdx_2#4 = phi(rdx_2#2, rdx_2#3) at the start of the block, like the one for dwSize#4

Steps To Reproduce:

  1. Open sacsess.tar.gz at CVTUTF8Scraper::Write (Addr: 0x140003750)
  2. Look at the MLIL representation of the blocks where rdx_2 is used.

Expected Behavior:
There should be phi function defining rdx_2#4

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Vector35/binaryninja-api

All issues in Vector35/binaryninja-api

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.