The afl fuzzer found a case where we tried reading an uleb for the DIE
abbrev code without properly checking the DIE address is inside the CU.
Signed-off-by: Mark Wielaard <mark@klomp.org>
2018-06-06 Mark Wielaard <mark@klomp.org>
+ * libdwP.h (__libdw_dieabbrev): Check DIE addr falls in cu.
+
+2018-06-06 Mark Wielaard <mark@klomp.org>
+
* dwarf_getlocation_die.c (dwarf_getlocation_die): Check offset
falls inside cu data.
/* Get the abbreviation code. */
unsigned int code;
const unsigned char *addr = die->addr;
- if (die->cu == NULL)
+ if (die->cu == NULL || addr >= (const unsigned char *) die->cu->endp)
return DWARF_END_ABBREV;
get_uleb128 (code, addr, die->cu->endp);
if (readp != NULL)