mirror of
https://github.com/RPCS3/llvm.git
synced 2026-07-19 15:13:49 -04:00
llvm-undname: Fix stack overflow on almost-valid
If a unsigned with all 4 bytes non-0 was passed to outputHex(), there were two off-by-ones in it: - Both MaxPos and Pos left space for the final \0, which left the buffer one byte to small. Set MaxPos to 16 instead of 15 to fix. - The `assert(Pos >= 0);` was after a `Pos--`, move it up one line. Since valid Unicode codepoints are <= 0x10ffff, this could never really happen in practice. Found by oss-fuzz. git-svn-id: https://llvm.org/svn/llvm-project/llvm/trunk@358856 91177308-0d34-0410-b5e6-96231b3b80d8
This commit is contained in:
@@ -1071,17 +1071,17 @@ static void outputHex(OutputStream &OS, unsigned C) {
|
||||
char TempBuffer[17];
|
||||
|
||||
::memset(TempBuffer, 0, sizeof(TempBuffer));
|
||||
constexpr int MaxPos = 15;
|
||||
constexpr int MaxPos = sizeof(TempBuffer) - 1;
|
||||
|
||||
int Pos = MaxPos - 1;
|
||||
int Pos = MaxPos - 1; // TempBuffer[MaxPos] is the terminating \0.
|
||||
while (C != 0) {
|
||||
for (int I = 0; I < 2; ++I) {
|
||||
writeHexDigit(&TempBuffer[Pos--], C % 16);
|
||||
C /= 16;
|
||||
}
|
||||
TempBuffer[Pos--] = 'x';
|
||||
TempBuffer[Pos--] = '\\';
|
||||
assert(Pos >= 0);
|
||||
TempBuffer[Pos--] = '\\';
|
||||
}
|
||||
OS << StringView(&TempBuffer[Pos + 1]);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user