[PATCH] D37070: [WebAssembly] Fix overflow for input without version

Jonas Devlieghere via Phabricator via llvm-commits llvm-commits at lists.llvm.org
Wed Aug 23 14:37:22 PDT 2017


This revision was automatically updated to reflect the committed changes.
Closed by commit rL311605: [WebAssembly] Fix overflow for input with missing version (authored by JDevlieghere).

Changed prior to commit:
  https://reviews.llvm.org/D37070?vs=112425&id=112458#toc

Repository:
  rL LLVM

https://reviews.llvm.org/D37070

Files:
  llvm/trunk/lib/Object/WasmObjectFile.cpp
  llvm/trunk/test/Object/Inputs/WASM/missing-version.wasm
  llvm/trunk/test/Object/wasm-missing-version.test


Index: llvm/trunk/lib/Object/WasmObjectFile.cpp
===================================================================
--- llvm/trunk/lib/Object/WasmObjectFile.cpp
+++ llvm/trunk/lib/Object/WasmObjectFile.cpp
@@ -203,15 +203,23 @@
                                   object_error::parse_failed);
     return;
   }
+
+  const uint8_t *Eof = getPtr(getData().size());
   const uint8_t *Ptr = getPtr(4);
+
+  if (Ptr + 4 > Eof) {
+    Err = make_error<StringError>("Missing version number",
+                                  object_error::parse_failed);
+    return;
+  }
+
   Header.Version = readUint32(Ptr);
   if (Header.Version != wasm::WasmVersion) {
     Err = make_error<StringError>("Bad version number",
                                   object_error::parse_failed);
     return;
   }
 
-  const uint8_t *Eof = getPtr(getData().size());
   WasmSection Sec;
   while (Ptr < Eof) {
     if ((Err = readSection(Sec, Ptr, getPtr(0))))
Index: llvm/trunk/test/Object/wasm-missing-version.test
===================================================================
--- llvm/trunk/test/Object/wasm-missing-version.test
+++ llvm/trunk/test/Object/wasm-missing-version.test
@@ -0,0 +1,2 @@
+# RUN: not llvm-objdump -h %p/Inputs/WASM/missing-version.wasm 2>&1 | FileCheck %s
+# CHECK: {{.*}}: Missing version number


-------------- next part --------------
A non-text attachment was scrubbed...
Name: D37070.112458.patch
Type: text/x-patch
Size: 1307 bytes
Desc: not available
URL: <http://lists.llvm.org/pipermail/llvm-commits/attachments/20170823/8ffa630c/attachment.bin>


More information about the llvm-commits mailing list