libdw: Check validity of dwarf_getabbrev arguments.
authorMark Wielaard <mark@klomp.org>
Fri, 8 Jun 2018 18:45:48 +0000 (20:45 +0200)
committerMark Wielaard <mark@klomp.org>
Mon, 11 Jun 2018 06:35:51 +0000 (08:35 +0200)
When the given Dwarf_Die was invalid we might crash and when the offset
was totally bogus we might succeed with a random abbrev.

Signed-off-by: Mark Wielaard <mark@klomp.org>
libdw/ChangeLog
libdw/dwarf_getabbrev.c
tests/ChangeLog
tests/get-units-invalid.c
tests/show-abbrev.c

index 21cb03c..1195cf6 100644 (file)
@@ -1,5 +1,9 @@
 2018-06-08  Mark Wielaard  <mark@klomp.org>
 
+       * dwarf_getabbrev.c (dwarf_getabbrev): Check die and offset.
+
+2018-06-08  Mark Wielaard  <mark@klomp.org>
+
        * dwarf_get_units.c (dwarf_get_units): Handle existing error, no
        dwarf.
 
index 1e113db..988d12c 100644 (file)
@@ -158,7 +158,21 @@ __libdw_getabbrev (Dwarf *dbg, struct Dwarf_CU *cu, Dwarf_Off offset,
 Dwarf_Abbrev *
 dwarf_getabbrev (Dwarf_Die *die, Dwarf_Off offset, size_t *lengthp)
 {
-  return __libdw_getabbrev (die->cu->dbg, die->cu,
-                           die->cu->orig_abbrev_offset + offset, lengthp,
-                           NULL);
+  if (die == NULL || die->cu == NULL)
+    return NULL;
+
+  Dwarf_CU *cu = die->cu;
+  Dwarf *dbg = cu->dbg;
+  Dwarf_Off abbrev_offset = cu->orig_abbrev_offset;
+  Elf_Data *data = dbg->sectiondata[IDX_debug_abbrev];
+  if (data == NULL)
+    return NULL;
+
+  if (offset >= data->d_size - abbrev_offset)
+    {
+      __libdw_seterrno (DWARF_E_INVALID_OFFSET);
+      return NULL;
+    }
+
+  return __libdw_getabbrev (dbg, cu, abbrev_offset + offset, lengthp, NULL);
 }
index 25ed41e..3b69a87 100644 (file)
@@ -1,5 +1,10 @@
 2018-06-08  Mark Wielaard  <mark@klomp.org>
 
+       * get-units-invalid.c (main): Check invalid dwarf_getabbrev call.
+       * show-abbrev.c (main): Check illegal dwarf_getabbrev offset call.
+
+2018-06-08  Mark Wielaard  <mark@klomp.org>
+
        * varlocs.c (main): Only assert when cfi_debug_bias != 0 if there
        actually is a cfi_debug.
 
index ba0f818..155e12d 100644 (file)
@@ -98,6 +98,12 @@ main (int argc, char *argv[])
                          dwarf_diename (&subdie));
                  return -1;
                }
+             if (dwarf_getabbrev (&subdie, 0, NULL) != NULL)
+               {
+                 printf ("Should NOT have an abbrev: %s\n",
+                         dwarf_diename (&subdie));
+                 return -1;
+               }
            }
          else if (unit_type == DW_UT_type)
            printf ("subdie: %s\n", dwarf_diename (&subdie));
index b0af029..002ae25 100644 (file)
@@ -51,6 +51,14 @@ main (int argc, char *argv[])
            /* Something went wrong.  */
            break;
 
+         /* Test something obviously wrong.  */
+         Dwarf_Abbrev *a = dwarf_getabbrev (&die, (Dwarf_Off) -1, NULL);
+         if (a != NULL)
+           {
+             printf ("dwarf_getabbrev -1 succeeded?\n");
+             break;
+           }
+
          Dwarf_Off offset = 0;
 
          while (1)