[PATCH] debugedit: Don't use alloca and sanity check line table dir/file counts
Mark Wielaard
mark@klomp.org
Mon Sep 7 13:10:05 GMT 2026
Hi,
On Tue, 2026-09-01 at 19:18 +0200, Mark Wielaard wrote:
> read_dwarf4_line would use alloca to store the (temporary) directory
> table, which could overflow the stack. Use malloc instead. Also sanity
> check the directory/file count (in both read_dwarf4_line, where value
> is always at least one and read_dwarf5_line, where zero is a valid
> value).
>
> * tools/debugedit.c (read_dwarf4_line): Initialize dirt to
> NULL, make value and dirt_cnt an uint64_t, sanitize value
> and malloc result, fee on return.
> (read_dwarf5_line_entries): Make entry_count a size_t, check
> entry_count is not zero, sanitize entry_count.
I pushed this to main.
Cheers,
Mark
More information about the Debugedit
mailing list