Reject overflowing integers in bytecode reader - #553
Open
carrerasdarren-cell wants to merge 1 commit into
Open
Conversation
Decode positive int fields through a uint32_t temporary and reject values above INT_MAX before assigning them. This prevents malformed counts from wrapping allocation-size calculations in JS_ReadFunctionTag. Add a binary-object regression for the overflowing constant-pool count from issue bellard#549.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
intfields through auint32_ttemporaryINT_MAXbefore assigning signed bytecode fieldsProblem
bc_get_leb128_int()previously wrote an unsigned LEB128 value directly through anint *. Values aboveINT_MAXtherefore became negative. InJS_ReadFunctionTag(), a negative count could wrap the allocation-size calculation below the bytecode-function header size before the header copy.The shared decoder now raises a
SyntaxErrorfor values that cannot be represented by its positiveintcallers. This also removes the incompatible pointer cast.Fixes #549.
Testing
make -j4 testmake -j4 CONFIG_ASAN=y CONFIG_UBSAN=y testSyntaxError: integer overflow while reading bytecode