[llvm] [Object][Wasm] Fix off-by-one in data segment name index validation (PR #196338)
via llvm-commits
llvm-commits at lists.llvm.org
Thu May 7 07:56:06 PDT 2026
llvmorg-github-actions[bot] wrote:
<!--LLVM PR SUMMARY COMMENT-->
@llvm/pr-subscribers-backend-webassembly
Author: KIM SO JUNG (sjg-388)
<details>
<summary>Changes</summary>
The check `Index > DataSegments.size()` in `parseNameSection()` allows
`Index == DataSegments.size()`, which is an out-of-bounds access.
In an assertions-disabled ASan build, a malformed wasm object with one
data segment and a data segment name entry using index 1 triggers a
heap-buffer-overflow READ in `WasmObjectFile::parseNameSection()`.
Fix by checking `Index >= DataSegments.size()` instead.
Also add a regression test that verifies the malformed input is rejected
with "invalid data segment name entry".
---
Full diff: https://github.com/llvm/llvm-project/pull/196338.diff
1 Files Affected:
- (modified) llvm/lib/Object/WasmObjectFile.cpp (+1-1)
``````````diff
diff --git a/llvm/lib/Object/WasmObjectFile.cpp b/llvm/lib/Object/WasmObjectFile.cpp
index 5f125ffb10198..f485095814157 100644
--- a/llvm/lib/Object/WasmObjectFile.cpp
+++ b/llvm/lib/Object/WasmObjectFile.cpp
@@ -600,7 +600,7 @@ Error WasmObjectFile::parseNameSection(ReadContext &Ctx) {
if (!SeenSegments.insert(Index).second)
return make_error<GenericBinaryError>(
"segment named more than once", object_error::parse_failed);
- if (Index > DataSegments.size())
+ if (static_cast<size_t>(Index) >= DataSegments.size())
return make_error<GenericBinaryError>("invalid data segment name entry",
object_error::parse_failed);
nameType = wasm::NameType::DATA_SEGMENT;
``````````
</details>
https://github.com/llvm/llvm-project/pull/196338
More information about the llvm-commits
mailing list