[PATCH] x86/CET: Don't parse beyond the note end

H.J. Lu hjl.tools@gmail.com
Fri Jul 27 18:47:00 GMT 2018


On Fri, Jul 27, 2018 at 11:26 AM, Florian Weimer <fweimer@redhat.com> wrote:
> On 07/27/2018 08:22 PM, H.J. Lu wrote:
>>
>> -         while (1)
>> +         while (ptr < ptr_end)
>>             {
>>               unsigned int type = *(unsigned int *) ptr;
>>               unsigned int datasz = *(unsigned int *) (ptr + 4);
>
>
> You need 1 byte, but 8 bytes.  Why is checking for at least 1 byte
> sufficient here?
>

There is:

          /* Check for invalid property.  */
          if (note->n_descsz < 8
              || (note->n_descsz % sizeof (ElfW(Addr))) != 0)
            break;

before that.   n_descsz should be correct.

-- 
H.J.



More information about the Libc-alpha mailing list