From patchwork Tue Apr 18 01:25:05 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alan Modra X-Patchwork-Id: 84514 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2513997vqo; Mon, 17 Apr 2023 18:25:22 -0700 (PDT) X-Google-Smtp-Source: AKy350bmt5mo+j25OMn8b5NjyOnC2XugEZaMlGGIfBeWpvYV7XiQMvi25yxXVnts7lM02138KGGb X-Received: by 2002:a17:907:a2cc:b0:94f:296d:75d0 with SMTP id re12-20020a170907a2cc00b0094f296d75d0mr8949159ejc.30.1681781122124; Mon, 17 Apr 2023 18:25:22 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681781122; cv=none; d=google.com; s=arc-20160816; b=jFvxA7AvvjwTVOF9R5f8dQJJExQ0zuYmArV4y+6Pj7d7Xzrhjz9CC97bgpCeDMvYU/ gkrfy59B69kSpaNduZnub+WzMnkYB94MAJiNRsqIjvS0h51Zgcah/KiBTfjgJtPW6lmV c7iKI9uw8PffwcoIekXxMbsmHTGSzx5e1XOSzjlU/O8ggW0bmOpMroKYzZjSpYG8Rnqo vm3nV4jG5yfJ7BCVs1ebaKfarNsMuYXWvG+4ydE9bSIJy/82L6uIMngWMxbMoTHFSWwX QWWvXhVbgrffcht/CekMtpYiDtGes/+4TROUghu8tU7dwsIwhLjujKCg29vWrYxYLdxa 3xJA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:reply-to:from:list-subscribe:list-help:list-post :list-archive:list-unsubscribe:list-id:precedence :content-disposition:mime-version:message-id:subject:to:date :dmarc-filter:delivered-to:dkim-signature:dkim-filter; bh=KNJbkkfXWMtTtrblzS8thESG1DE+BNxCGZjeA1gSUCM=; b=uxvQNQKfG8LUrfx1KYmDV0MTmii28uvqVmEwJ/3a7yldGp8VdrdT4fWZeWHFe3EJEB WsIIblI99xv7ZLjZW6UqUMLeRm+iO2sQTF/uI9y9hYgJLghOTkj+YvLFngXZjATFSFwy 0R/sn2JMvSbdtBe/NM7B9JaNV3nxGMhfsGjjEyBxkNkzhcRFaVC3saOKcz4uyTvF0xn8 zD0gv4kZ5R+mrF4k12WqzJaLaccQIPSYaz4brGTzi/B+QLGX80hNq3w6UgYIz3cJWgWE xusGOg4DzcpaLjXGaM2cmTwi/gGKshUg0x95CQ/BsyHObeguxJtteJj/6PyVYabK634l 1uUA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=AvJzVIGn; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from sourceware.org (server2.sourceware.org. [2620:52:3:1:0:246e:9693:128c]) by mx.google.com with ESMTPS id ez4-20020a1709070bc400b0094f2be3e094si4755539ejc.261.2023.04.17.18.25.21 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Apr 2023 18:25:22 -0700 (PDT) Received-SPF: pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) client-ip=2620:52:3:1:0:246e:9693:128c; Authentication-Results: mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=AvJzVIGn; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id B93583858C50 for ; Tue, 18 Apr 2023 01:25:20 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B93583858C50 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sourceware.org; s=default; t=1681781120; bh=KNJbkkfXWMtTtrblzS8thESG1DE+BNxCGZjeA1gSUCM=; h=Date:To:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post: List-Help:List-Subscribe:From:Reply-To:From; b=AvJzVIGn4iCZk5JT17K5lsEiQbULuoaAxLJTFT9Jk+VG8aPn0sgl2x2hy6y2Sbhp7 CKIG1aR7i2g9Usqra6HzRo90EWBtku2dYbgpwr7IO1z8jqTWzYnYvBGyeCbKDwl9vg wFYwUL3Hx84AFL8A65oB8vCEgk6/T5oW20N8WIiY= X-Original-To: binutils@sourceware.org Delivered-To: binutils@sourceware.org Received: from mail-pl1-x634.google.com (mail-pl1-x634.google.com [IPv6:2607:f8b0:4864:20::634]) by sourceware.org (Postfix) with ESMTPS id 772F93858D28 for ; Tue, 18 Apr 2023 01:25:11 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 772F93858D28 Received: by mail-pl1-x634.google.com with SMTP id d9443c01a7336-1a677dffb37so12045995ad.2 for ; Mon, 17 Apr 2023 18:25:11 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1681781110; x=1684373110; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=KNJbkkfXWMtTtrblzS8thESG1DE+BNxCGZjeA1gSUCM=; b=jY5uJ/aJG3LPck6kwYxarKDbueL9PfbUWwaG7Z6YuBAWk4e+XaPX2dDSudmv8Ij3EQ w+Js8UL8i6ZpN2iMd2AVZPCiucBWgj2LTm5G4xmFMRJuWtMnIyYxM1xtPh1fX5GIYcyN MwQZXXi04Gjd/X/DCPkYiadquKonNB86k690PayGUIkv/lx5fwUXJ6iZW3TIyJ+YJX2I wHsQA8zEiJZy6Md8mTSWUkgOCjfQDGaP/OqMve1yRfQhCVTPH1nUR9jMfxGn/4U843yd 9o5BBXglZfJnJrCLhAyCf3pgDDc6Pr8bqzbKORraRoBG/sKJEjuG+8fT6uRVmgR5iipO mqHw== X-Gm-Message-State: AAQBX9d/xZ+gzAo8iK1B3S4PaUd7Nsbwr64F60wDUQQHgwHSfjkibcO9 bPtW/+fep+v3Wewja/sSx4uvnJ9b5ik= X-Received: by 2002:a17:902:d489:b0:1a2:185d:4eef with SMTP id c9-20020a170902d48900b001a2185d4eefmr508819plg.10.1681781109863; Mon, 17 Apr 2023 18:25:09 -0700 (PDT) Received: from squeak.grove.modra.org ([2406:3400:51d:8cc0:c26a:e69d:7ab8:56d6]) by smtp.gmail.com with ESMTPSA id ja13-20020a170902efcd00b0019682e27995sm2620260plb.223.2023.04.17.18.25.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Apr 2023 18:25:08 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id A07691142D7F; Tue, 18 Apr 2023 10:55:05 +0930 (ACST) Date: Tue, 18 Apr 2023 10:55:05 +0930 To: binutils@sourceware.org Subject: objdump buffer overflow in fetch_indexed_string Message-ID: MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-3034.5 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Patchwork-Original-From: Alan Modra via Binutils From: Alan Modra Reply-To: Alan Modra Errors-To: binutils-bounces+ouuuleilei=gmail.com@sourceware.org Sender: "Binutils" X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1763475322109922296?= X-GMAIL-MSGID: =?utf-8?q?1763475322109922296?= PR 30361 * dwarf.c (fetch_indexed_string): Sanity check string index. diff --git a/binutils/dwarf.c b/binutils/dwarf.c index 87ce1541d1c..86893c59dc7 100644 --- a/binutils/dwarf.c +++ b/binutils/dwarf.c @@ -659,14 +659,13 @@ fetch_indexed_string (uint64_t idx, return (dwo ? _("") : _("")); - index_offset = idx * offset_size; - - if (this_set != NULL) - index_offset += this_set->section_offsets [DW_SECT_STR_OFFSETS]; - - index_offset += str_offsets_base; - - if (index_offset + offset_size > index_section->size) + if (_mul_overflow (idx, offset_size, &index_offset) + || (this_set != NULL + && ((index_offset += this_set->section_offsets [DW_SECT_STR_OFFSETS]) + < this_set->section_offsets [DW_SECT_STR_OFFSETS])) + || (index_offset += str_offsets_base) < str_offsets_base + || index_offset + offset_size < offset_size + || index_offset + offset_size > index_section->size) { warn (_("string index of %" PRIu64 " converts to an offset of %#" PRIx64 " which is too big for section %s"), @@ -675,11 +674,6 @@ fetch_indexed_string (uint64_t idx, return _(""); } - /* FIXME: If we are being paranoid then we should also check to see if - IDX references an entry beyond the end of the string table pointed to - by STR_OFFSETS_BASE. (Since there can be more than one string table - in a DWARF string section). */ - str_offset = byte_get (index_section->start + index_offset, offset_size); str_offset -= str_section->address;