mirror of
https://github.com/openharmony/third_party_elfutils.git
synced 2026-07-19 19:43:34 -04:00
readelf: Sanity check CIE unit_length and augmentationlen in debug_frame.
Signed-off-by: Mark Wielaard <mjw@redhat.com>
This commit is contained in:
@@ -1,3 +1,8 @@
|
||||
2014-11-14 Mark Wielaard <mjw@redhat.com>
|
||||
|
||||
* readelf.c (print_debug_frame_section): Sanity Check CIE
|
||||
unit_length and augmentationlen.
|
||||
|
||||
2014-11-14 Mark Wielaard <mjw@redhat.com>
|
||||
|
||||
* readelf.c (handle_versym): Check def == NULL before use.
|
||||
|
||||
+16
-1
@@ -5332,6 +5332,10 @@ print_debug_frame_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr,
|
||||
continue;
|
||||
}
|
||||
|
||||
Dwarf_Word maxsize = dataend - readp;
|
||||
if (unlikely (unit_length > maxsize))
|
||||
goto invalid_data;
|
||||
|
||||
unsigned int ptr_size = ehdr->e_ident[EI_CLASS] == ELFCLASS32 ? 4 : 8;
|
||||
|
||||
ptrdiff_t start = readp - (unsigned char *) data->d_buf;
|
||||
@@ -5413,7 +5417,11 @@ print_debug_frame_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr,
|
||||
get_uleb128 (augmentationlen, readp);
|
||||
|
||||
if (augmentationlen > (size_t) (dataend - readp))
|
||||
error (1, 0, gettext ("invalid augmentation length"));
|
||||
{
|
||||
error (0, 0, gettext ("invalid augmentation length"));
|
||||
readp = cieend;
|
||||
continue;
|
||||
}
|
||||
|
||||
const char *hdr = "Augmentation data:";
|
||||
const char *cp = augmentation + 1;
|
||||
@@ -5561,6 +5569,13 @@ print_debug_frame_section (Dwfl_Module *dwflmod, Ebl *ebl, GElf_Ehdr *ehdr,
|
||||
unsigned int augmentationlen;
|
||||
get_uleb128 (augmentationlen, readp);
|
||||
|
||||
if (augmentationlen > (size_t) (dataend - readp))
|
||||
{
|
||||
error (0, 0, gettext ("invalid augmentation length"));
|
||||
readp = cieend;
|
||||
continue;
|
||||
}
|
||||
|
||||
if (augmentationlen > 0)
|
||||
{
|
||||
const char *hdr = "Augmentation data:";
|
||||
|
||||
Reference in New Issue
Block a user