Vector35 / Vector35/binaryninja-api

Unnecessary `cs` segment override prefix (in Win32 flat mode) breaks jump table lifting

Open
#8,477 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Version and Platform (required):

  • Binary Ninja Version: 5.3.9757 Personal (a99f2380)
  • OS: macOS
  • OS Version: 26.6.1
  • CPU Architecture: ARM64

Bug Description:
I have a Win32 user-mode binary from the 90s that, for whatever reason, contains a redundant 0x2e segment override prefix on a jmp [sib] opcode, where the SIB encodes a jump table which follows immediately afterwards (all absolute addresses, not position-independent).

Binary Ninja decides to turn this into an "Unresolved Indirect Control Flow" even though this segment override has no effect in Win32.

If I manually patch the segment override prefix into a nop in the hex editor view, this is able to work around the problem (in only that specific instance, of course).

Steps To Reproduce:
Please provide all steps required to reproduce the behavior:

  1. Load a binary that contains an unnecessary segment override as I've shown
  2. Look in the disassembly view and notice the large red ? question mark.
  3. Look in the LLIL view and see cs.d as part of the jump computation.
  4. Patch the 0x2e to 0x90 in the hex editor. Observe that everything works now.

Expected Behavior:
x86 segment overrides should be ignored on platforms where they are known to not do anything (which includes most modern userspace, for segments other than fs/gs)

Screenshots/Video Recording:
Screenshots of Binary Ninja seeing the segment override:

Image Image

Screenshot after manual patches in the hex editor

Image

Binary:
Unfortunately, I do not have permission to share the binary.

Additional Information:
N/A

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing x86 decoding of the 0x2e prefix and LLIL generation for the jmp [sib] sequence described in the issue. Check how Win32 flat-mode segment semantics are represented, then add a regression case for an equivalent instruction sequence if the test framework permits. Done means inert cs overrides no longer contribute cs.d or prevent jump-table lifting, while fs/gs behavior remains unchanged.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.