[PATCH] x86/CET: Don't parse beyond the note end
H.J. Lu
hjl.tools@gmail.com
Fri Jul 27 18:47:00 GMT 2018
On Fri, Jul 27, 2018 at 11:26 AM, Florian Weimer <fweimer@redhat.com> wrote:
> On 07/27/2018 08:22 PM, H.J. Lu wrote:
>>
>> - while (1)
>> + while (ptr < ptr_end)
>> {
>> unsigned int type = *(unsigned int *) ptr;
>> unsigned int datasz = *(unsigned int *) (ptr + 4);
>
>
> You need 1 byte, but 8 bytes. Why is checking for at least 1 byte
> sufficient here?
>
There is:
/* Check for invalid property. */
if (note->n_descsz < 8
|| (note->n_descsz % sizeof (ElfW(Addr))) != 0)
break;
before that. n_descsz should be correct.
--
H.J.
More information about the Libc-alpha
mailing list