[llvm] [Object][Wasm] Fix off-by-one in data segment name index validation (PR #196338)

via llvm-commits llvm-commits at lists.llvm.org
Thu May 7 07:56:06 PDT 2026


llvmorg-github-actions[bot] wrote:


<!--LLVM PR SUMMARY COMMENT-->

@llvm/pr-subscribers-backend-webassembly

Author: KIM SO JUNG (sjg-388)

<details>
<summary>Changes</summary>

The check `Index > DataSegments.size()` in `parseNameSection()` allows
`Index == DataSegments.size()`, which is an out-of-bounds access.

In an assertions-disabled ASan build, a malformed wasm object with one
data segment and a data segment name entry using index 1 triggers a
heap-buffer-overflow READ in `WasmObjectFile::parseNameSection()`.

Fix by checking `Index >= DataSegments.size()` instead.

Also add a regression test that verifies the malformed input is rejected
with "invalid data segment name entry".

---
Full diff: https://github.com/llvm/llvm-project/pull/196338.diff


1 Files Affected:

- (modified) llvm/lib/Object/WasmObjectFile.cpp (+1-1) 


``````````diff
diff --git a/llvm/lib/Object/WasmObjectFile.cpp b/llvm/lib/Object/WasmObjectFile.cpp
index 5f125ffb10198..f485095814157 100644
--- a/llvm/lib/Object/WasmObjectFile.cpp
+++ b/llvm/lib/Object/WasmObjectFile.cpp
@@ -600,7 +600,7 @@ Error WasmObjectFile::parseNameSection(ReadContext &Ctx) {
           if (!SeenSegments.insert(Index).second)
             return make_error<GenericBinaryError>(
                 "segment named more than once", object_error::parse_failed);
-          if (Index > DataSegments.size())
+          if (static_cast<size_t>(Index) >= DataSegments.size())
             return make_error<GenericBinaryError>("invalid data segment name entry",
                                                   object_error::parse_failed);
           nameType = wasm::NameType::DATA_SEGMENT;

``````````

</details>


https://github.com/llvm/llvm-project/pull/196338


More information about the llvm-commits mailing list