summaryrefslogtreecommitdiffstats
path: root/llvm
diff options
context:
space:
mode:
authorNico Weber <nicolasweber@gmx.de>2019-04-21 14:25:07 +0000
committerNico Weber <nicolasweber@gmx.de>2019-04-21 14:25:07 +0000
commitaa162682ca23907d463635534b987b4defa22d24 (patch)
tree07da61e91c01ead268bfe9abe96f3f716acc4e30 /llvm
parentf985e3125428c41ec253f08d824ba00f7acb1320 (diff)
downloadbcm5719-llvm-aa162682ca23907d463635534b987b4defa22d24.tar.gz
bcm5719-llvm-aa162682ca23907d463635534b987b4defa22d24.zip
llvm-undname: Fix stack overflow on invalid found by oss-fuzz
llvm-svn: 358852
Diffstat (limited to 'llvm')
-rw-r--r--llvm/lib/Demangle/MicrosoftDemangle.cpp2
-rw-r--r--llvm/test/Demangle/invalid-manglings.test5
2 files changed, 6 insertions, 1 deletions
diff --git a/llvm/lib/Demangle/MicrosoftDemangle.cpp b/llvm/lib/Demangle/MicrosoftDemangle.cpp
index 6431e4ab130..b421f2a7f93 100644
--- a/llvm/lib/Demangle/MicrosoftDemangle.cpp
+++ b/llvm/lib/Demangle/MicrosoftDemangle.cpp
@@ -1292,7 +1292,7 @@ Demangler::demangleStringLiteral(StringView &MangledName) {
unsigned BytesDecoded = 0;
while (!MangledName.consumeFront('@')) {
- if (MangledName.size() < 1)
+ if (MangledName.size() < 1 || BytesDecoded >= MaxStringByteLength)
goto StringLiteralError;
StringBytes[BytesDecoded++] = demangleCharLiteral(MangledName);
}
diff --git a/llvm/test/Demangle/invalid-manglings.test b/llvm/test/Demangle/invalid-manglings.test
index ef37518e54a..fb66c2b1cda 100644
--- a/llvm/test/Demangle/invalid-manglings.test
+++ b/llvm/test/Demangle/invalid-manglings.test
@@ -159,3 +159,8 @@
; CHECK-EMPTY:
; CHECK-NEXT: ??_C@_1301234567@a
; CHECK-NEXT: error: Invalid mangled name
+
+??_C@_0601234567@abcdefghijklmnopqrtsuvwxyzABCDEFGHIJKLMNOPQRTSUVWXYZabcdefghijklmnopqrtsuvwxyzABCDEFGHIJKLMNOPQRTSUVWXYZabcdefghijklmnopqrtsuvwxyz
+; CHECK-EMPTY:
+; CHECK-NEXT: ??_C@_0601234567@abcdefghijklmnopqrtsuvwxyzABCDEFGHIJKLMNOPQRTSUVWXYZabcdefghijklmnopqrtsuvwxyzABCDEFGHIJKLMNOPQRTSUVWXYZabcdefghijklmnopqrtsuvwxyz
+; CHECK-NEXT: error: Invalid mangled name
OpenPOWER on IntegriCloud