diff --git a/include/llvm/Object/ELF.h b/include/llvm/Object/ELF.h index d1de25d2821..2c715bffa2f 100644 --- a/include/llvm/Object/ELF.h +++ b/include/llvm/Object/ELF.h @@ -347,6 +347,12 @@ ELFFile::ELFFile(StringRef Object, std::error_code &EC) // The getNumSections() call below depends on SectionHeaderTable being set. SectionHeaderTable = reinterpret_cast(base() + SectionTableOffset); + if (getNumSections() > UINT64_MAX / Header->e_shentsize) { + // Section table goes past end of file! + EC = object_error::parse_failed; + return; + } + const uint64_t SectionTableSize = getNumSections() * Header->e_shentsize; if (SectionTableOffset + SectionTableSize > FileSize) { diff --git a/test/Object/Inputs/invalid-sections-num.elf b/test/Object/Inputs/invalid-sections-num.elf new file mode 100644 index 00000000000..d8d5bc8fe2b Binary files /dev/null and b/test/Object/Inputs/invalid-sections-num.elf differ diff --git a/test/Object/invalid.test b/test/Object/invalid.test index a0016fef9d5..dd431aa3a55 100644 --- a/test/Object/invalid.test +++ b/test/Object/invalid.test @@ -76,3 +76,6 @@ INVALID-SEC-ADDRESS-ALIGNMENT: Invalid data was encountered while parsing the fi RUN: not llvm-readobj -t %p/Inputs/invalid-section-size2.elf 2>&1 | \ RUN: FileCheck --check-prefix=INVALID-SECTION-SIZE2 %s INVALID-SECTION-SIZE2: Invalid data was encountered while parsing the file. + +RUN: not llvm-readobj -t %p/Inputs/invalid-sections-num.elf 2>&1 | FileCheck --check-prefix=INVALID-SECTION-NUM %s +INVALID-SECTION-NUM: Invalid data was encountered while parsing the file.