Change the for loop so that we can always read a full element. https://sourceware.org/bugzilla/show_bug.cgi?id=22892
Signed-off-by: Mark Wielaard <m...@klomp.org> --- src/ChangeLog | 5 +++++ src/elflint.c | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/src/ChangeLog b/src/ChangeLog index 0ae01e92..e73c6154 100644 --- a/src/ChangeLog +++ b/src/ChangeLog @@ -1,3 +1,8 @@ +2018-02-09 Mark Wielaard <m...@klomp.org> + + * elflint.c (check_group): Make sure we can read a complete + element when iterating over the group. + 2018-02-09 Mark Wielaard <m...@klomp.org> * readelf.c (attr_callback): Handle DW_FORM_data16 as Dwarf_Block. diff --git a/src/elflint.c b/src/elflint.c index df1b3a03..ebb0e4e0 100644 --- a/src/elflint.c +++ b/src/elflint.c @@ -2713,7 +2713,7 @@ section [%2d] '%s': section group with only one member\n"), ERROR (gettext ("section [%2d] '%s': unknown section group flags\n"), idx, section_name (ebl, idx)); - for (cnt = elsize; cnt < data->d_size; cnt += elsize) + for (cnt = elsize; cnt + elsize <= data->d_size; cnt += elsize) { #if ALLOW_UNALIGNED val = *((Elf32_Word *) ((char *) data->d_buf + cnt)); -- 2.16.1