[all-commits] [llvm/llvm-project] 82576d: [libunwind] Fix UB in EHHeaderParser::findFDE

Jorge Gorbe Moya via All-commits all-commits at lists.llvm.org
Tue Apr 7 14:47:36 PDT 2020


  Branch: refs/heads/master
  Home:   https://github.com/llvm/llvm-project
  Commit: 82576d6fecfec71725eb900111c000d772002449
      https://github.com/llvm/llvm-project/commit/82576d6fecfec71725eb900111c000d772002449
  Author: Jorge Gorbe Moya <jgorbe at google.com>
  Date:   2020-04-07 (Tue, 07 Apr 2020)

  Changed paths:
    M libunwind/src/EHHeaderParser.hpp

  Log Message:
  -----------
  [libunwind] Fix UB in EHHeaderParser::findFDE

When the EHHeaderInfo object filled by decodeEHHdr has fde_count == 0,
findFDE does the following:

- sets low = 0 and len = hdrInfo.fde_count as a preparation to start a
  binary search
- because len is 0, the binary search loop is skipped
- the code still tries to find a table entry at
  hdrInfo.table + low * tableEntrySize, and decode it.

This is wrong when fde_count is 0, and trying to decode a table entry
that isn't there will lead to reading garbage offsets and can cause
segfaults.

Differential Revision: https://reviews.llvm.org/D77679




More information about the All-commits mailing list