mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
__KernelLoadELFFromPtr creates its PSPModule and inserts it into loadedModules before it knows whether the file is loadable, so every failure exit has to delete the decrypt buffer, Cleanup() the module and Destroy() it. Five of the seven did. The "unreasonable decrypted size" exit and the decompression-failure exit just returned - leaking the buffer, and leaving a live kernel object with its UID stuck in loadedModules for the rest of the session. While tracing that: the fake-module path frees newptr and then runs for another sixty lines with ptr still pointing into it. Nothing reads it today - the exits below use head, which points into the original input rather than the copy - so there's no use-after-free and no double free, but that's a property of the current code rather than anything enforced. Both pointers are nulled after the delete so a future mistake there crashes instead of reading freed heap. And the function read the magic, and in the ~SCE branch a second word after it, before anything established the input was that big. The non-PBP caller guarantees it, but the PBP path computes elfSize from two offsets in the file and passes whatever comes out, including zero. Checked at the top, before the module object exists, so that exit needs no cleanup of its own. pspautotests 314/314 with --graphics=software, and an EBOOT.PBP still boots. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9