[llvm] a3a4550 - [Object] Widen data size calculation to 64-bits to prevent overflow (#224635)

via llvm-commits llvm-commits at lists.llvm.org
Wed Sep 23 04:00:51 PDT 2026


Author: Igor Wodiany
Date: 2026-09-23T12:00:43+01:00
New Revision: a3a45508d77ca1fa8161c85baaf5e64bc9b8be39

URL: https://github.com/llvm/llvm-project/commit/a3a45508d77ca1fa8161c85baaf5e64bc9b8be39
DIFF: https://github.com/llvm/llvm-project/commit/a3a45508d77ca1fa8161c85baaf5e64bc9b8be39.diff

LOG: [Object] Widen data size calculation to 64-bits to prevent overflow (#224635)

This patch widens selected operands of the product calculation to
`size_t`/`uint64_t` to prevent multiplication overflow when a 64-bit
data size or offset is being calculated. This fixes a number of issues
reported by a CodeQL scan.

Added: 
    

Modified: 
    llvm/include/llvm/Object/DXContainer.h
    llvm/lib/Object/DXContainer.cpp
    llvm/lib/Object/MachOObjectFile.cpp

Removed: 
    


################################################################################
diff  --git a/llvm/include/llvm/Object/DXContainer.h b/llvm/include/llvm/Object/DXContainer.h
index 36ede1b21330e..90ed2633a6608 100644
--- a/llvm/include/llvm/Object/DXContainer.h
+++ b/llvm/include/llvm/Object/DXContainer.h
@@ -210,7 +210,8 @@ struct DescriptorTableView : RootParameterView {
     Current += sizeof(uint32_t);
 
     Table.Ranges.Data = ParamData.substr(2 * sizeof(uint32_t),
-                                         Table.NumRanges * Table.Ranges.Stride);
+                                         static_cast<size_t>(Table.NumRanges) *
+                                             Table.Ranges.Stride);
     return Table;
   }
 };

diff  --git a/llvm/lib/Object/DXContainer.cpp b/llvm/lib/Object/DXContainer.cpp
index e7641077b5029..b3c39d330357b 100644
--- a/llvm/lib/Object/DXContainer.cpp
+++ b/llvm/lib/Object/DXContainer.cpp
@@ -775,7 +775,8 @@ Error DirectX::PSVRuntimeInfo::parse(uint16_t ShaderKind) {
       return Err;
     Current += sizeof(uint32_t);
 
-    size_t BindingDataSize = Resources.Stride * ResourceCount;
+    size_t BindingDataSize =
+        static_cast<size_t>(Resources.Stride) * ResourceCount;
     Resources.Data = Data.substr(Current - Data.begin(), BindingDataSize);
 
     if (Resources.Data.size() < BindingDataSize)

diff  --git a/llvm/lib/Object/MachOObjectFile.cpp b/llvm/lib/Object/MachOObjectFile.cpp
index c926159ce04df..85c4f69d70dde 100644
--- a/llvm/lib/Object/MachOObjectFile.cpp
+++ b/llvm/lib/Object/MachOObjectFile.cpp
@@ -2699,11 +2699,9 @@ basic_symbol_iterator MachOObjectFile::symbol_end() const {
   if (!SymtabLoadCmd || Symtab.nsyms == 0)
     return basic_symbol_iterator(SymbolRef(DRI, this));
 
-  unsigned SymbolTableEntrySize = is64Bit() ?
-    sizeof(MachO::nlist_64) :
-    sizeof(MachO::nlist);
-  unsigned Offset = Symtab.symoff +
-    Symtab.nsyms * SymbolTableEntrySize;
+  uint64_t SymbolTableEntrySize =
+      is64Bit() ? sizeof(MachO::nlist_64) : sizeof(MachO::nlist);
+  uint64_t Offset = Symtab.symoff + Symtab.nsyms * SymbolTableEntrySize;
   DRI.p = reinterpret_cast<uintptr_t>(getPtr(*this, Offset));
   return basic_symbol_iterator(SymbolRef(DRI, this));
 }
@@ -2712,8 +2710,8 @@ symbol_iterator MachOObjectFile::getSymbolByIndex(unsigned Index) const {
   MachO::symtab_command Symtab = getSymtabLoadCommand();
   if (!SymtabLoadCmd || Index >= Symtab.nsyms)
     report_fatal_error("Requested symbol index is out of range.");
-  unsigned SymbolTableEntrySize =
-    is64Bit() ? sizeof(MachO::nlist_64) : sizeof(MachO::nlist);
+  uint64_t SymbolTableEntrySize =
+      is64Bit() ? sizeof(MachO::nlist_64) : sizeof(MachO::nlist);
   DataRefImpl DRI;
   DRI.p = reinterpret_cast<uintptr_t>(getPtr(*this, Symtab.symoff));
   DRI.p += Index * SymbolTableEntrySize;


        


More information about the llvm-commits mailing list