[llvm] 4a49d09 - [DebugInfo] Fix overflow in DWARFDebugLine::SectionParser (#224770)

via llvm-commits llvm-commits at lists.llvm.org
Mon Sep 21 14:01:05 PDT 2026


Author: Jonas Devlieghere
Date: 2026-09-21T14:00:56-07:00
New Revision: 4a49d09c3358c6ac54362d9a8ef8075a4b121114

URL: https://github.com/llvm/llvm-project/commit/4a49d09c3358c6ac54362d9a8ef8075a4b121114
DIFF: https://github.com/llvm/llvm-project/commit/4a49d09c3358c6ac54362d9a8ef8075a4b121114.diff

LOG: [DebugInfo] Fix overflow in DWARFDebugLine::SectionParser (#224770)

Adding a DWARF64 unit length can overflow and wrap back into the
section, causing an infinite loop. Saturate the addition so an
overflowing offset fails the bounds check.

rdar://186810393

Added: 
    

Modified: 
    llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
    llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp

Removed: 
    


################################################################################
diff  --git a/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp b/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
index 1da46a596539b..2cdbe64f4ce0c 100644
--- a/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
+++ b/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
@@ -18,6 +18,7 @@
 #include "llvm/Support/Errc.h"
 #include "llvm/Support/FormatAdapters.h"
 #include "llvm/Support/FormatVariadic.h"
+#include "llvm/Support/MathExtras.h"
 #include "llvm/Support/raw_ostream.h"
 #include <algorithm>
 #include <cassert>
@@ -1656,7 +1657,9 @@ void DWARFDebugLine::SectionParser::moveToNextTable(uint64_t OldOffset,
     return;
   }
 
-  Offset = OldOffset + P.TotalLength + P.sizeofTotalLength();
+  // Prevent an overflowing length from wrapping back into the section.
+  Offset = SaturatingAdd(OldOffset, P.TotalLength,
+                         static_cast<uint64_t>(P.sizeofTotalLength()));
   if (!DebugLineData.isValidOffset(Offset)) {
     Done = true;
     return;

diff  --git a/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp b/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
index 537dc32490a0f..b2156bf1772dc 100644
--- a/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
+++ b/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
@@ -13,6 +13,7 @@
 #include "llvm/Object/ObjectFile.h"
 #include "llvm/Testing/Support/Error.h"
 #include "gtest/gtest.h"
+#include <limits>
 
 // AIX doesn't support the debug_addr section
 #ifdef _AIX
@@ -1397,6 +1398,25 @@ TEST_F(DebugLineBasicFixture, ParserMarkedAsDoneForBadLengthWhenSkipping) {
           "reserved unit length of value 0xfffffff0"));
 }
 
+TEST_F(DebugLineBasicFixture, ParserMarkedAsDoneForOverflowingLength) {
+  if (!setupGenerator())
+    GTEST_SKIP();
+
+  LineTable &LT = Gen->addLineTable(DWARF64);
+  // Wrap the next offset back to the start of the table.
+  LT.setCustomPrologue(
+      {{dwarf::DW_LENGTH_DWARF64, LineTable::Long},
+       {std::numeric_limits<uint64_t>::max() - 11, LineTable::Quad}});
+  generate();
+
+  DWARFDebugLine::SectionParser Parser(LineData, *Context, Units);
+  Parser.parseNext(RecordRecoverable, RecordUnrecoverable);
+
+  EXPECT_TRUE(Parser.done());
+  EXPECT_FALSE(Recoverable);
+  EXPECT_THAT_ERROR(std::move(Unrecoverable), Failed());
+}
+
 TEST_F(DebugLineBasicFixture, ParserReportsFirstErrorInEachTableWhenParsing) {
   if (!setupGenerator())
     GTEST_SKIP();


        


More information about the llvm-commits mailing list