Defend against junk PT_DYNAMIC

https://github.com/upx/upx/issues/390
	modified:   p_lx_elf.cpp
This commit is contained in:
John Reiser 2020-07-23 04:14:34 -07:00 committed by Markus F.X.J. Oberhumer
parent 0016512df1
commit 73b854874e

View File

@ -5042,7 +5042,7 @@ PackLinuxElf32::check_pt_dynamic(Elf32_Phdr const *const phdr)
unsigned vaddr = get_te32(&phdr->p_vaddr);
unsigned filesz = get_te32(&phdr->p_filesz), memsz = get_te32(&phdr->p_memsz);
unsigned align = get_te32(&phdr->p_align);
if (s < t || (u32_t)file_size < s
if (s < t || (u32_t)file_size < s || t < sizeof(Elf32_Ehdr)
|| (3 & t) || (7 & (filesz | memsz)) // .balign 4; 8==sizeof(Elf32_Dyn)
|| (-1+ align) & (t ^ vaddr)
|| (unsigned long)file_size <= memsz
@ -5144,7 +5144,7 @@ PackLinuxElf64::check_pt_dynamic(Elf64_Phdr const *const phdr)
upx_uint64_t vaddr = get_te64(&phdr->p_vaddr);
upx_uint64_t filesz = get_te64(&phdr->p_filesz), memsz = get_te64(&phdr->p_memsz);
upx_uint64_t align = get_te64(&phdr->p_align);
if (s < t || (upx_uint64_t)file_size < s
if (s < t || (upx_uint64_t)file_size < s || t < sizeof(Elf64_Ehdr)
|| (7 & t) || (0xf & (filesz | memsz)) // .balign 8; 16==sizeof(Elf64_Dyn)
|| (-1+ align) & (t ^ vaddr)
|| (unsigned long)file_size <= memsz