[COMMITTED] libdw: Check there are any header bytes in loclists

Mark Wielaard mark@klomp.org
Sat Jul 11 15:45:29 GMT 2026


We tried to read the loclists header length and only then checked if
there were any bytes left. Make sure to check there are at least 4
bytes for the initial unit length.

	* libdw/libdwP.h (__libdw_cu_locs_base): Check before initial
	unit_length read.

https://sourceware.org/bugzilla/show_bug.cgi?id=34386

Reported-by: Karan Kurani <karankurani3k@gmail.com>
Signed-off-by: Mark Wielaard <mark@klomp.org>
---
 libdw/libdwP.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/libdw/libdwP.h b/libdw/libdwP.h
index 25391396ff6b..1a3aea2d99ec 100644
--- a/libdw/libdwP.h
+++ b/libdw/libdwP.h
@@ -1458,6 +1458,8 @@ __libdw_cu_locs_base (Dwarf_CU *cu)
 	  const unsigned char *const dataend
 	    = (unsigned char *) data->d_buf + data->d_size;
 
+	  if (unlikely (readp > dataend - 4))
+	    goto no_header;
 	  uint64_t unit_length = read_4ubyte_unaligned_inc (dbg, readp);
 	  unsigned int offset_size = 4;
 	  if (unlikely (unit_length == 0xffffffff))
-- 
2.55.0



More information about the Elfutils-devel mailing list