The buffer read in needs to contain room for at least one Elf32_Dyn or
Elf64_Dyn entry.

Signed-off-by: Mark Wielaard <m...@klomp.org>
---
 libdwfl/ChangeLog  | 5 +++++
 libdwfl/link_map.c | 5 +++++
 2 files changed, 10 insertions(+)

diff --git a/libdwfl/ChangeLog b/libdwfl/ChangeLog
index f849b816..d4eee639 100644
--- a/libdwfl/ChangeLog
+++ b/libdwfl/ChangeLog
@@ -1,3 +1,8 @@
+2021-12-16  Mark Wielaard  <m...@klomp.org>
+
+       * link_map.c (dwfl_link_map_report): Make sure dyn_filesz / entsize is
+       non-zero.
+
 2021-12-08  Mark Wielaard  <m...@klomp.org>
 
        * dwfl_segment_report_module.c (dwfl_segment_report_module): Add
diff --git a/libdwfl/link_map.c b/libdwfl/link_map.c
index 82df7b69..177ad9a5 100644
--- a/libdwfl/link_map.c
+++ b/libdwfl/link_map.c
@@ -1017,6 +1017,11 @@ dwfl_link_map_report (Dwfl *dwfl, const void *auxv, 
size_t auxv_size,
                 in.d_size. The data might have been truncated.  */
              if (dyn_filesz > in.d_size)
                dyn_filesz = in.d_size;
+             if (dyn_filesz / entsize == 0)
+               {
+                 __libdwfl_seterrno (DWFL_E_BADELF);
+                 return false;
+               }
              void *buf = malloc (dyn_filesz);
              Elf32_Dyn (*d32)[dyn_filesz / sizeof (Elf32_Dyn)] = buf;
              Elf64_Dyn (*d64)[dyn_filesz / sizeof (Elf64_Dyn)] = buf;
-- 
2.30.2

Reply via email to