[PATCH] D38512: Added phdr upper bound checks to ElfObject

Parker Thompson via Phabricator via llvm-commits llvm-commits at lists.llvm.org
Wed Oct 4 13:15:14 PDT 2017


mothran updated this revision to Diff 117723.
mothran edited the summary of this revision.

https://reviews.llvm.org/D38512

Files:
  include/llvm/Object/ELF.h
  test/Object/Inputs/invalid-phdr.elf
  test/Object/elf-invalid-phdr.test


Index: test/Object/elf-invalid-phdr.test
===================================================================
--- /dev/null
+++ test/Object/elf-invalid-phdr.test
@@ -0,0 +1,3 @@
+RUN: not llvm-objdump -private-headers %p/Inputs/invalid-phdr.elf
+
+LLVM ERROR: Invalid data was encountered while parsing the file
Index: include/llvm/Object/ELF.h
===================================================================
--- include/llvm/Object/ELF.h
+++ include/llvm/Object/ELF.h
@@ -144,6 +144,8 @@
   Expected<Elf_Phdr_Range> program_headers() const {
     if (getHeader()->e_phnum && getHeader()->e_phentsize != sizeof(Elf_Phdr))
       return createError("invalid e_phentsize");
+    if (getHeader()->e_phoff + (getHeader()->e_phnum * getHeader()->e_phentsize) > getBufSize())
+      return createError("program headers longer than binary");
     auto *Begin =
         reinterpret_cast<const Elf_Phdr *>(base() + getHeader()->e_phoff);
     return makeArrayRef(Begin, Begin + getHeader()->e_phnum);


-------------- next part --------------
A non-text attachment was scrubbed...
Name: D38512.117723.patch
Type: text/x-patch
Size: 996 bytes
Desc: not available
URL: <http://lists.llvm.org/pipermail/llvm-commits/attachments/20171004/50407ff1/attachment.bin>


More information about the llvm-commits mailing list