[llvm] 4a49d09 - [DebugInfo] Fix overflow in DWARFDebugLine::SectionParser (#224770)
via llvm-commits
llvm-commits at lists.llvm.org
Mon Sep 21 14:01:05 PDT 2026
Author: Jonas Devlieghere
Date: 2026-09-21T14:00:56-07:00
New Revision: 4a49d09c3358c6ac54362d9a8ef8075a4b121114
URL: https://github.com/llvm/llvm-project/commit/4a49d09c3358c6ac54362d9a8ef8075a4b121114
DIFF: https://github.com/llvm/llvm-project/commit/4a49d09c3358c6ac54362d9a8ef8075a4b121114.diff
LOG: [DebugInfo] Fix overflow in DWARFDebugLine::SectionParser (#224770)
Adding a DWARF64 unit length can overflow and wrap back into the
section, causing an infinite loop. Saturate the addition so an
overflowing offset fails the bounds check.
rdar://186810393
Added:
Modified:
llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
Removed:
################################################################################
diff --git a/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp b/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
index 1da46a596539b..2cdbe64f4ce0c 100644
--- a/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
+++ b/llvm/lib/DebugInfo/DWARF/DWARFDebugLine.cpp
@@ -18,6 +18,7 @@
#include "llvm/Support/Errc.h"
#include "llvm/Support/FormatAdapters.h"
#include "llvm/Support/FormatVariadic.h"
+#include "llvm/Support/MathExtras.h"
#include "llvm/Support/raw_ostream.h"
#include <algorithm>
#include <cassert>
@@ -1656,7 +1657,9 @@ void DWARFDebugLine::SectionParser::moveToNextTable(uint64_t OldOffset,
return;
}
- Offset = OldOffset + P.TotalLength + P.sizeofTotalLength();
+ // Prevent an overflowing length from wrapping back into the section.
+ Offset = SaturatingAdd(OldOffset, P.TotalLength,
+ static_cast<uint64_t>(P.sizeofTotalLength()));
if (!DebugLineData.isValidOffset(Offset)) {
Done = true;
return;
diff --git a/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp b/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
index 537dc32490a0f..b2156bf1772dc 100644
--- a/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
+++ b/llvm/unittests/DebugInfo/DWARF/DWARFDebugLineTest.cpp
@@ -13,6 +13,7 @@
#include "llvm/Object/ObjectFile.h"
#include "llvm/Testing/Support/Error.h"
#include "gtest/gtest.h"
+#include <limits>
// AIX doesn't support the debug_addr section
#ifdef _AIX
@@ -1397,6 +1398,25 @@ TEST_F(DebugLineBasicFixture, ParserMarkedAsDoneForBadLengthWhenSkipping) {
"reserved unit length of value 0xfffffff0"));
}
+TEST_F(DebugLineBasicFixture, ParserMarkedAsDoneForOverflowingLength) {
+ if (!setupGenerator())
+ GTEST_SKIP();
+
+ LineTable < = Gen->addLineTable(DWARF64);
+ // Wrap the next offset back to the start of the table.
+ LT.setCustomPrologue(
+ {{dwarf::DW_LENGTH_DWARF64, LineTable::Long},
+ {std::numeric_limits<uint64_t>::max() - 11, LineTable::Quad}});
+ generate();
+
+ DWARFDebugLine::SectionParser Parser(LineData, *Context, Units);
+ Parser.parseNext(RecordRecoverable, RecordUnrecoverable);
+
+ EXPECT_TRUE(Parser.done());
+ EXPECT_FALSE(Recoverable);
+ EXPECT_THAT_ERROR(std::move(Unrecoverable), Failed());
+}
+
TEST_F(DebugLineBasicFixture, ParserReportsFirstErrorInEachTableWhenParsing) {
if (!setupGenerator())
GTEST_SKIP();
More information about the llvm-commits
mailing list