From 73b854874e723f38e84e5ff57a9eeb99653ca74c Mon Sep 17 00:00:00 2001 From: John Reiser Date: Thu, 23 Jul 2020 04:14:34 -0700 Subject: [PATCH] Defend against junk PT_DYNAMIC https://github.com/upx/upx/issues/390 modified: p_lx_elf.cpp --- src/p_lx_elf.cpp | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/p_lx_elf.cpp b/src/p_lx_elf.cpp index 453d5c45..80bf4be3 100644 --- a/src/p_lx_elf.cpp +++ b/src/p_lx_elf.cpp @@ -5042,7 +5042,7 @@ PackLinuxElf32::check_pt_dynamic(Elf32_Phdr const *const phdr) unsigned vaddr = get_te32(&phdr->p_vaddr); unsigned filesz = get_te32(&phdr->p_filesz), memsz = get_te32(&phdr->p_memsz); unsigned align = get_te32(&phdr->p_align); - if (s < t || (u32_t)file_size < s + if (s < t || (u32_t)file_size < s || t < sizeof(Elf32_Ehdr) || (3 & t) || (7 & (filesz | memsz)) // .balign 4; 8==sizeof(Elf32_Dyn) || (-1+ align) & (t ^ vaddr) || (unsigned long)file_size <= memsz @@ -5144,7 +5144,7 @@ PackLinuxElf64::check_pt_dynamic(Elf64_Phdr const *const phdr) upx_uint64_t vaddr = get_te64(&phdr->p_vaddr); upx_uint64_t filesz = get_te64(&phdr->p_filesz), memsz = get_te64(&phdr->p_memsz); upx_uint64_t align = get_te64(&phdr->p_align); - if (s < t || (upx_uint64_t)file_size < s + if (s < t || (upx_uint64_t)file_size < s || t < sizeof(Elf64_Ehdr) || (7 & t) || (0xf & (filesz | memsz)) // .balign 8; 16==sizeof(Elf64_Dyn) || (-1+ align) & (t ^ vaddr) || (unsigned long)file_size <= memsz