summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRafael Espindola <rafael.espindola@gmail.com>2017-10-19 01:25:48 +0000
committerRafael Espindola <rafael.espindola@gmail.com>2017-10-19 01:25:48 +0000
commit55680d0addfa6536f9d51217fa814e8aa4889824 (patch)
tree8099a0b0008e0c482df3742a2139e0c8e6482aea
parent2a0a8fb6bcd8b223b2c9174aa39b7199cf072e5d (diff)
downloadbcm5719-llvm-55680d0addfa6536f9d51217fa814e8aa4889824.tar.gz
bcm5719-llvm-55680d0addfa6536f9d51217fa814e8aa4889824.zip
Fix buffer overflow.
We were reading past the end of the buffer. llvm-svn: 316143
-rw-r--r--llvm/lib/BinaryFormat/Magic.cpp2
-rw-r--r--llvm/test/Object/Inputs/invalid-coff-header-too-smallbin0 -> 64 bytes
-rw-r--r--llvm/test/Object/invalid.test3
3 files changed, 4 insertions, 1 deletions
diff --git a/llvm/lib/BinaryFormat/Magic.cpp b/llvm/lib/BinaryFormat/Magic.cpp
index e9b8df93b90..db8e9526e64 100644
--- a/llvm/lib/BinaryFormat/Magic.cpp
+++ b/llvm/lib/BinaryFormat/Magic.cpp
@@ -185,7 +185,7 @@ file_magic llvm::identify_magic(StringRef Magic) {
if (startswith(Magic, "MZ") && Magic.size() >= 0x3c + 4) {
uint32_t off = read32le(Magic.data() + 0x3c);
// PE/COFF file, either EXE or DLL.
- if (off < Magic.size() &&
+ if (off + sizeof(COFF::PEMagic) <= Magic.size() &&
memcmp(Magic.data() + off, COFF::PEMagic, sizeof(COFF::PEMagic)) == 0)
return file_magic::pecoff_executable;
}
diff --git a/llvm/test/Object/Inputs/invalid-coff-header-too-small b/llvm/test/Object/Inputs/invalid-coff-header-too-small
new file mode 100644
index 00000000000..c9f0c965b76
--- /dev/null
+++ b/llvm/test/Object/Inputs/invalid-coff-header-too-small
Binary files differ
diff --git a/llvm/test/Object/invalid.test b/llvm/test/Object/invalid.test
index b0b5528ab05..6899f5ab057 100644
--- a/llvm/test/Object/invalid.test
+++ b/llvm/test/Object/invalid.test
@@ -86,3 +86,6 @@ INVALID-REL-SYM: invalid section offset
RUN: not llvm-readobj -r %p/Inputs/invalid-buffer.elf 2>&1 | FileCheck --check-prefix=INVALID-BUFFER %s
INVALID-BUFFER: Invalid buffer
+
+RUN: not llvm-readobj %p/Inputs/invalid-coff-header-too-small 2>&1 | FileCheck --check-prefix=COFF-HEADER %s
+COFF-HEADER: The file was not recognized as a valid object file
OpenPOWER on IntegriCloud