Avoid possible pointer wrap
Alan Modra
amodra@gmail.com
Mon May 10 01:09:11 GMT 2021
PTR supplied to these macros can be read from user input, END is an
end of buffer pointer. It's safer to do arithmetic on END than on PTR.
* dwarf.c (SAFE_BYTE_GET): Check bounds by subtracting amount from
END rather than adding amount to PTR.
(SAFE_SIGNED_BYTE_GET, SAFE_BYTE_GET64): Likewise.
diff --git a/binutils/dwarf.c b/binutils/dwarf.c
index d93d9239684..c584f5b2a24 100644
--- a/binutils/dwarf.c
+++ b/binutils/dwarf.c
@@ -406,7 +406,7 @@ read_leb128 (unsigned char *data,
amount, (int) sizeof (VAL)); \
amount = sizeof (VAL); \
} \
- if (((PTR) + amount) >= (END)) \
+ if ((PTR) >= (END) - amount) \
{ \
if ((PTR) < (END)) \
amount = (END) - (PTR); \
@@ -434,7 +434,7 @@ read_leb128 (unsigned char *data,
do \
{ \
unsigned int amount = (AMOUNT); \
- if (((PTR) + amount) >= (END)) \
+ if ((PTR) >= (END) - amount) \
{ \
if ((PTR) < (END)) \
amount = (END) - (PTR); \
@@ -460,7 +460,7 @@ read_leb128 (unsigned char *data,
#define SAFE_BYTE_GET64(PTR, HIGH, LOW, END) \
do \
{ \
- if (((PTR) + 8) <= (END)) \
+ if ((PTR) <= (END) - 8) \
{ \
byte_get_64 ((PTR), (HIGH), (LOW)); \
} \
--
Alan Modra
Australia Development Lab, IBM
More information about the Binutils
mailing list