Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Newlines in filenames can inject ARM assembly

COMPCERT-586

Affected product
CompCert
Severity
High
Weakness
CWE-77
Disclosed

Summary

A newline in a source filename could escape the ARM command-line comment and add attacker-controlled instructions to the assembled object.

Technical analysis

The accompanying research article explains the finding, reproduction, and remediation status.

Read the technical write-up

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References