summaryrefslogtreecommitdiffstats
path: root/llvm/lib/Bitcode
diff options
context:
space:
mode:
authorFilipe Cabecinhas <me@filcab.net>2015-05-16 00:33:12 +0000
committerFilipe Cabecinhas <me@filcab.net>2015-05-16 00:33:12 +0000
commit1c299d05e6b75d5bdc87239aa7136773df44783e (patch)
tree9714f6e33e93f2b379ee7b2248118b0faf0358d7 /llvm/lib/Bitcode
parent341eda4ca7981650db6c519692861f5913f67ecc (diff)
downloadbcm5719-llvm-1c299d05e6b75d5bdc87239aa7136773df44783e.tar.gz
bcm5719-llvm-1c299d05e6b75d5bdc87239aa7136773df44783e.zip
[BitcodeReader] Don't allow INSERTVAL/EXTRACTVAL with 0 indices
This would trigger an assertion later. Bug found with AFL fuzz. llvm-svn: 237494
Diffstat (limited to 'llvm/lib/Bitcode')
-rw-r--r--llvm/lib/Bitcode/Reader/BitcodeReader.cpp14
1 files changed, 10 insertions, 4 deletions
diff --git a/llvm/lib/Bitcode/Reader/BitcodeReader.cpp b/llvm/lib/Bitcode/Reader/BitcodeReader.cpp
index 743466051a1..e0800916c8c 100644
--- a/llvm/lib/Bitcode/Reader/BitcodeReader.cpp
+++ b/llvm/lib/Bitcode/Reader/BitcodeReader.cpp
@@ -3555,10 +3555,13 @@ std::error_code BitcodeReader::ParseFunctionBody(Function *F) {
if (getValueTypePair(Record, OpNum, NextValueNo, Agg))
return Error("Invalid record");
+ unsigned RecSize = Record.size();
+ if (OpNum == RecSize)
+ return Error("EXTRACTVAL: Invalid instruction with 0 indices");
+
SmallVector<unsigned, 4> EXTRACTVALIdx;
Type *CurTy = Agg->getType();
- for (unsigned RecSize = Record.size();
- OpNum != RecSize; ++OpNum) {
+ for (; OpNum != RecSize; ++OpNum) {
bool IsArray = CurTy->isArrayTy();
bool IsStruct = CurTy->isStructTy();
uint64_t Index = Record[OpNum];
@@ -3594,10 +3597,13 @@ std::error_code BitcodeReader::ParseFunctionBody(Function *F) {
if (getValueTypePair(Record, OpNum, NextValueNo, Val))
return Error("Invalid record");
+ unsigned RecSize = Record.size();
+ if (OpNum == RecSize)
+ return Error("INSERTVAL: Invalid instruction with 0 indices");
+
SmallVector<unsigned, 4> INSERTVALIdx;
Type *CurTy = Agg->getType();
- for (unsigned RecSize = Record.size();
- OpNum != RecSize; ++OpNum) {
+ for (; OpNum != RecSize; ++OpNum) {
bool IsArray = CurTy->isArrayTy();
bool IsStruct = CurTy->isStructTy();
uint64_t Index = Record[OpNum];
OpenPOWER on IntegriCloud