# github.com/twitchyliquid64/golang-asm@v0.15.1 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:40.000Z
- Files reviewed: 104
- Findings: 3 medium, 8 low severity findings
- Report: https://security.togoder.click/go/github.com/twitchyliquid64/golang-asm
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/twitchyliquid64/golang-asm@v0.15.1 on Oct 5, 2026. An AI review of 104 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Lack of input validation on object file data

Finding ID: `NPS-5526BF3FB335`

File: `goobj/objfile.go:476`

The `Reader` methods compute offsets and lengths based on the header's `Offsets` array without validating that they are within the bounds of the provided byte slice. A malicious object file could cause panics (index out of range) or out-of-bounds reads, potentially leading to denial of service or memory corruption.

### [medium] Potential out-of-bounds read

Finding ID: `NPS-9B239EF72029`

File: `goobj/objfile.go:636`

Several methods use `unsafe.Pointer` to cast byte slices to structs (e.g., `Sym`, `Reloc`, `Aux`). There is no bounds checking in these casts, which could lead to out-of-bounds reads if the object file is malformed. This is a common pattern in low-level parsers but can be exploited to cause crashes or information disclosure.

### [medium] File system manipulation / Response file expansion

Finding ID: `NPS-F17D43E2A11C`

File: `objabi/flag.go:45`

The expandArgs function reads arbitrary files specified by '@filename' command-line arguments using ioutil.ReadFile(s[1:]). This enables an attacker who can influence command-line arguments to cause the tool to read any file readable by the process. While not inherently malicious and matching documented Go toolchain behavior, it is an unusual file-read capability that could be abused for data exfiltration if combined with other flaws.

### [low] external process execution

Finding ID: `NPS-73ED6E49D2BB`

File: `dwarf/dwarf.go:732`

The function IsDWARFEnabledOnAIXLd executes an external linker binary (extld) with the -Wl,-V flag to check its version on AIX. This is a legitimate, narrowly scoped use for DWARF configuration on AIX and does not perform arbitrary command execution or shell injection. No user-controlled input is interpolated into a shell, and no suspicious behavior is present.

### [low] Unsafe string construction from read-only memory

Finding ID: `NPS-025661200781`

File: `goobj/objfile.go:594`

The `toString` function uses `unsafe.Pointer` to convert a byte slice backed by read-only memory into a string without copying. If the underlying memory is later modified (e.g., via unsafe pointers elsewhere), it could lead to data corruption or security issues. However, the code checks `r.readonly` before calling it, so the risk is mitigated.

### [low] Use of `unsafe` package for performance

Finding ID: `NPS-FA52C120820A`

File: `goobj/objfile.go:594`

The code extensively uses `unsafe` to reinterpret byte slices as structs and to create strings without copying. While this is typical for performance-critical parsers, it increases the risk of memory safety issues if not carefully audited.

### [low] init-time registration

Finding ID: `NPS-A9197299A78F`

File: `obj/arm/list5.go:33`

The init() function registers ARM register/opcode formatting handlers with the Go object package. This is normal for Go toolchain libraries and only mutates in-process tables; it performs no network, filesystem, or process operations.

### [low] Go init function

Finding ID: `NPS-7C1016961F9C`

File: `obj/ppc64/a.out.go:213`

The file contains an init() function that populates a DWARF register mapping table. It only performs local map assignments and makes no network, file system, or process calls, so it is not a malicious install-time or import-time payload.

### [low] init() function

Finding ID: `NPS-8D4F7E92CB65`

File: `obj/riscv/list.go:11`

The init() function registers register and opcode names for the RISC-V architecture with the Go assembler framework. This is a standard, benign pattern in Go assembler packages and does not perform any file, network, or process operations.

### [low] init function

Finding ID: `NPS-E152602F2F76`

File: `obj/x86/evex.go:155`

The file contains an init() function that runs at import time, but it only populates an in-memory lookup table (evexSuffixMap) from a static internal table. It performs no network, filesystem, process, or dynamic code execution activity.

### [low] Process termination

Finding ID: `NPS-4762BF7F1500`

File: `objabi/flag.go:97`

versionFlag.Set calls os.Exit(0) during flag parsing. This matches expected Go toolchain behavior for -V flag but represents top-level execution behavior that terminates the process when triggered by specific input.

## Files reviewed

- `goobj/objfile.go` (medium): The code is a low-level object file parser with several unsafe memory operations and missing bounds checks, posing a moderate risk if fed untrusted input, but no direct malicious patterns were found.
- `objabi/flag.go` (medium): This appears to be a legitimate Go toolchain package (cmd/internal/objabi) with documented response-file expansion and version flag handling; no clear malicious intent, but the arbitrary file read via @files and process exit warrant a warning.
- `asm/arch/arch.go` (safe): Cleared by Jev triage; no further analysis needed
- `asm/arch/arm.go` (safe): Cleared by Jev triage; no further analysis needed
- `asm/arch/arm64.go` (safe): Cleared by Jev triage; no further analysis needed
- `asm/arch/mips.go` (safe): Cleared by Jev triage; no further analysis needed
- `asm/arch/ppc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `asm/arch/riscv64.go` (safe): Cleared by Jev triage; no further analysis needed
- `asm/arch/s390x.go` (safe): Cleared by Jev triage; no further analysis needed
- `bio/buf.go` (safe): No malicious patterns detected
- `bio/buf_mmap.go` (safe): No malicious patterns detected; the code is a standard memory-mapped file reader from the Go standard library's internal bio package with only legitimate OS-level memory mapping.
- `bio/buf_nommap.go` (safe): Cleared by Jev triage; no further analysis needed
- `bio/must.go` (safe): Cleared by Jev triage; no further analysis needed
- `builder.go` (safe): Cleared by Jev triage; no further analysis needed
- `dwarf/dwarf.go` (safe): This is the standard Go standard-library dwarf package; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or install-time hooks are present.
- `dwarf/dwarf_defs.go` (safe): Cleared by Jev triage; no further analysis needed
- `goobj/builtin.go` (safe): No malicious patterns detected
- `goobj/builtinlist.go` (safe): No malicious patterns detected; this is a generated Go runtime builtin symbol table with no executable code, network access, or file system manipulation.
- `goobj/funcinfo.go` (safe): Cleared by Jev triage; no further analysis needed
- `goobj/mkbuiltin.go` (safe): No malicious patterns detected
- `obj/abi_string.go` (safe): No malicious patterns detected
- `obj/addrtype_string.go` (safe): No malicious patterns detected
- `obj/arm/a.out.go` (safe): This file contains only ARM architecture constant definitions and a DWARF register mapping initialization; no malicious patterns were detected.
- `obj/arm/anames.go` (safe): No malicious patterns detected
- `obj/arm/anames5.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm/asm5.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm/list5.go` (safe): This is a benign ARM disassembly/formatting helper derived from the Inferno/Plan 9 toolchain with no malicious patterns, network activity, filesystem access, or dynamic code execution.
- `obj/arm/obj5.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm64/a.out.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm64/anames.go` (safe): No malicious patterns detected
- `obj/arm64/anames7.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm64/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm64/list7.go` (safe): No malicious patterns detected; this file is standard Go assembler register and opcode formatting code for the ARM64 architecture.
- `obj/arm64/obj7.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/arm64/sysRegEnc.go` (safe): No malicious patterns detected
- `obj/data.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/dwarf.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/go.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/inl.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/ld.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/line.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/link.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/mips/a.out.go` (safe): This file contains only MIPS architecture constant definitions and register mappings with no malicious patterns, network activity, or code execution beyond simple initialization checks.
- `obj/mips/anames.go` (safe): No malicious patterns detected
- `obj/mips/anames0.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/mips/asm0.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/mips/list0.go` (safe): No malicious patterns detected
- `obj/mips/obj0.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/objfile.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/pass.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/pcln.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/plist.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/ppc64/a.out.go` (safe): This is a standard Go architecture definitions file for ppc64 with only constants, register mappings, and a benign init() function; no malicious patterns were detected.
- `obj/ppc64/anames.go` (safe): No malicious patterns detected; the file is a generated stringer output containing only PowerPC instruction name constants.
- `obj/ppc64/anames9.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/ppc64/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/ppc64/list9.go` (safe): No malicious patterns detected; the file contains only register/opcode name formatting for the Go assembler's ppc64 backend.
- `obj/ppc64/obj9.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/riscv/anames.go` (safe): No malicious patterns detected
- `obj/riscv/cpu.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/riscv/inst.go` (safe): Generated RISC-V instruction encoding table with no executable logic, network calls, or malicious patterns detected.
- `obj/riscv/list.go` (safe): No malicious patterns detected; the code is a benign RISC-V register/opcode name registration for the Go assembler, with no network, filesystem, credential, or process activity.
- `obj/riscv/obj.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/s390x/a.out.go` (safe): No malicious patterns detected; the file contains only standard Go definitions for s390x architecture constants, register mappings, and DWARF register initialization within an assembler library.
- `obj/s390x/anames.go` (safe): No malicious patterns detected
- `obj/s390x/anamesz.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/s390x/condition_code.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/s390x/listz.go` (safe): No malicious patterns detected; the file is a standard Go assembler register/opcode name formatter with only init registration and string formatting.
- `obj/s390x/objz.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/s390x/rotate.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/s390x/vector.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/stringer.go` (safe): No malicious patterns detected
- `obj/sym.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/textflag.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/util.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/wasm/a.out.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/wasm/anames.go` (safe): No malicious patterns detected; this is a generated list of WebAssembly opcode names used by a Go assembler package.
- `obj/wasm/wasmobj.go` (safe): This is a legitimate Go WebAssembly assembler backend from the Go standard library (golang-asm) with no malicious patterns detected.
- `obj/x86/a.out.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/x86/aenum.go` (safe): No malicious patterns detected
- `obj/x86/anames.go` (safe): No malicious patterns detected
- `obj/x86/evex.go` (safe): No malicious patterns detected; the init() function only performs benign in-memory initialization of EVEX suffix lookup data with no exfiltration, credential access, dynamic execution, or external I/O.
- `obj/x86/list6.go` (safe): No malicious patterns detected
- `obj/x86/obj6.go` (safe): Cleared by Jev triage; no further analysis needed
- `obj/x86/ytab.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/autotype.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/funcdata.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/funcid.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/head.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/line.go` (safe): This is a standard Go standard library utility file for path rewriting and prefix matching with no malicious patterns detected.
- `objabi/path.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/reloctype.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/reloctype_string.go` (safe): No malicious patterns detected; this is a standard auto-generated stringer file for Go's RelocType enum with no external interactions, dynamic code execution, or suspicious behavior.
- `objabi/stack.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/symkind.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/symkind_string.go` (safe): No malicious patterns detected
- `objabi/typekind.go` (safe): Cleared by Jev triage; no further analysis needed
- `objabi/util.go` (safe): No malicious patterns detected; the code is standard Go toolchain configuration logic from the official Go source tree.
- `src/pos.go` (safe): Cleared by Jev triage; no further analysis needed
- `src/xpos.go` (safe): Cleared by Jev triage; no further analysis needed
- `sys/arch.go` (safe): Cleared by Jev triage; no further analysis needed
- `sys/supported.go` (safe): Cleared by Jev triage; no further analysis needed
- `unsafeheader/unsafeheader.go` (safe): The code is a standard, non-malicious Go package containing type declarations for slice and string headers; it contains no red-flag patterns.
- `unsafeheader/unsafeheader/unsafeheader.go` (safe): The code is a standard, non-malicious Go package containing type declarations for slice and string headers; it contains no red-flag patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
