Avoid possible pointer wrap

Alan Modra amodra@gmail.com
Mon May 10 01:09:11 GMT 2021


PTR supplied to these macros can be read from user input, END is an
end of buffer pointer.  It's safer to do arithmetic on END than on PTR.

	* dwarf.c (SAFE_BYTE_GET): Check bounds by subtracting amount from
	END rather than adding amount to PTR.
	(SAFE_SIGNED_BYTE_GET, SAFE_BYTE_GET64): Likewise.

diff --git a/binutils/dwarf.c b/binutils/dwarf.c
index d93d9239684..c584f5b2a24 100644
--- a/binutils/dwarf.c
+++ b/binutils/dwarf.c
@@ -406,7 +406,7 @@ read_leb128 (unsigned char *data,
 		 amount, (int) sizeof (VAL));	\
 	  amount = sizeof (VAL);		\
 	}					\
-      if (((PTR) + amount) >= (END))		\
+      if ((PTR) >= (END) - amount)		\
 	{					\
 	  if ((PTR) < (END))			\
 	    amount = (END) - (PTR);		\
@@ -434,7 +434,7 @@ read_leb128 (unsigned char *data,
   do							\
     {							\
       unsigned int amount = (AMOUNT);			\
-      if (((PTR) + amount) >= (END))			\
+      if ((PTR) >= (END) - amount)			\
 	{						\
 	  if ((PTR) < (END))				\
 	    amount = (END) - (PTR);			\
@@ -460,7 +460,7 @@ read_leb128 (unsigned char *data,
 #define SAFE_BYTE_GET64(PTR, HIGH, LOW, END)		\
   do							\
     {							\
-      if (((PTR) + 8) <= (END))				\
+      if ((PTR) <= (END) - 8)				\
 	{						\
 	  byte_get_64 ((PTR), (HIGH), (LOW));		\
 	}						\

-- 
Alan Modra
Australia Development Lab, IBM


More information about the Binutils mailing list