So today musl discovered a longstanding bug in Linux's ELF loader
twitter.com
twitter.com
I thought dynamically linked binaries are still ELF, but have special code to load shared object files into the right places in memory.
The elf interpreter is then responsible for loading the file into memory, handling all the shared library linking or other special operations, and then jumps to actual programs start point as specified by elf header. Generally it does it by parsing the elf headers, resolving all the symbols recursively, and calling mmap() to properly allocate memory for the program as well as to mmap() the program text and libraries into memory.
So there are two loaders involved even if kernel had only one, because the kernel loader is simplified and doesn't handle full scope of ELF nor is it supposed to handle dynamic linking.
Is this heartbleed for ELF, or is the junk always mapped from the ELF binary itself (or the ldd binary, whose content is ostensibly common knowledge)?
So there is random unzeroed junk at the end of BSS, which only bites us with release optimizations. Sounds security to me
Coming from a Rust enjoyer. Don't use it myself but see the benefits. But those oneliners always make me chuckle.