aboutsummaryrefslogtreecommitdiff
path: root/include/coff
diff options
context:
space:
mode:
authorNick Clifton <nickc@redhat.com>2018-03-13 14:02:52 +0000
committerNick Clifton <nickc@redhat.com>2018-03-13 14:02:52 +0000
commit3e33b239450771394fa6c83b67b9de80169f35e8 (patch)
tree41501559be5295fda0d75f60a14c4bf2b5ef19e9 /include/coff
parentb0d186effc0af8d5f5f012895a194e7e01d4804c (diff)
downloadbinutils-3e33b239450771394fa6c83b67b9de80169f35e8.zip
binutils-3e33b239450771394fa6c83b67b9de80169f35e8.tar.gz
binutils-3e33b239450771394fa6c83b67b9de80169f35e8.tar.bz2
Prevent memory access violations when attempting to parse an x86_64 PE binary containing corrupt unwind information.
PR 22113 incldue * coff/pe.h (struct pex64_unwind_info): Add a rawUnwindCodesEnd field. bfd * pei-x86_64.c (pex64_get_unwind_info): Change to a boolean function. Add an end address parameter. Check access of the data pointer to make sure that they do not extend beyond the end address. Return FALSE if any check fails. Add the end address pointer to the ui structure. (pex64_xdata_print_uwd_codes): Check accesses of the raw unwind codes to make sure that they do not extend beyond the end address pointer. Print an error message and return immediately if any check fails.
Diffstat (limited to 'include/coff')
-rw-r--r--include/coff/pe.h1
1 files changed, 1 insertions, 0 deletions
diff --git a/include/coff/pe.h b/include/coff/pe.h
index 56cc4e2..cb9075a 100644
--- a/include/coff/pe.h
+++ b/include/coff/pe.h
@@ -497,6 +497,7 @@ struct pex64_unwind_info
bfd_vma FrameOffset;
bfd_vma sizeofUnwindCodes;
bfd_byte *rawUnwindCodes;
+ bfd_byte *rawUnwindCodesEnd;
bfd_vma rva_ExceptionHandler; /* UNW_EHANDLER or UNW_FLAG_UHANDLER. */
bfd_vma rva_BeginAddress; /* UNW_FLAG_CHAININFO. */
bfd_vma rva_EndAddress; /* UNW_FLAG_CHAININFO. */