Vector35 / Vector35/binaryninja-api

Analysis falters with x86 code that has pattern "push addr; ret" in a lot of functions

Open
#6,191 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Effort: Medium Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

While analyzing 9b7ccaa2ae6a5b96e3110ebcbc4311f6.dll_.zip, I observe we bail out on a lot of functions relying on analysis.limits.maxFunctionUpdateCount. A closer look at the code reveals the following pattern at the end of almost all functions:

Screenshot 2024-11-25 at 12 16 26 PM

We actually handle such a case when it occurs on individual functions. However, since every function has it, the analysis falters and do not handle it gracefully. If I force the analysis of the function, the analysis will get into an infinite loop

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue with the linked 9b7ccaa2ae6a5b96e3110ebcbc4311f6.dll_.zip and inspect handling of analysis.limits.maxFunctionUpdateCount. Compare the behavior with the existing individual-function handling for the “push addr; ret” pattern. Done means analysis completes without widespread bailouts or an infinite loop.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.