[PATCH 1/8] elf: Bound the tunable cache string table against the mapping size
DJ Delorie
dj@redhat.com
Thu Jul 9 02:02:44 GMT 2026
Adhemerval Zanella <adhemerval.zanella@linaro.org> writes:
> - /* Validate each entry. */
> - int s_start = (const char *) (&cache_new->libs[cache_new->nlibs]) - *data;
> - int s_end = s_start + cache_new->len_strings;
> + /* Validate each entry. The string table lies between the file entries
> + and the end of the mapping; clamp its end to CACHESIZE so that a bogus
> + len_strings cannot make an offset point outside the mapped file. */
> + size_t s_start = (const char *) (&cache_new->libs[cache_new->nlibs]) - *data;
s_start is always set
> + size_t s_end;
> + if (s_start >= cachesize
> + || INT_ADD_WRAPV (s_start, cache_new->len_strings, &s_end))
> + return NULL;
s_end might be set here, but we return if not
> + if (s_end > cachesize)
> + s_end = cachesize;
s_end is definitely set here.
LGTM
Reviewed-by: DJ Delorie <dj@redhat.com>
More information about the Libc-alpha
mailing list