git: f15642e24db7 - main - imgact_aout: Widen the overflow checks in exec_aout_imgact()
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 29 Sep 2026 18:58:39 UTC
The branch main has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=f15642e24db7d16c63ce484924d9075926dbf58a
commit f15642e24db7d16c63ce484924d9075926dbf58a
Author: Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-29 18:56:22 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 18:56:22 +0000
imgact_aout: Widen the overflow checks in exec_aout_imgact()
I suspect this overflow check isn't needed at all, at least today, since
vm_map_insert() will detect wraparound when it creates segments (and
even a check against UINT_MAX is too loose, since the max user address
is AOUT32_USRSTACK == 0xbfc00000). But if we're going to keep this
check, there doesn't seem to be any downside to applying it on all
platforms, before exec_new_vmspace() tears down the current vmspace.
Reported by: Muhammed Sariyildiz <asiyee994@gmail.com>
Reviewed by: kib
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60027
---
sys/kern/imgact_aout.c | 16 ++++++----------
1 file changed, 6 insertions(+), 10 deletions(-)
diff --git a/sys/kern/imgact_aout.c b/sys/kern/imgact_aout.c
index 9978c74f0dee..86ee8f6913b9 100644
--- a/sys/kern/imgact_aout.c
+++ b/sys/kern/imgact_aout.c
@@ -236,17 +236,13 @@ exec_aout_imgact(struct image_params *imgp)
*/
if (/* entry point must lay with text region */
a_out->a_entry < virtual_offset ||
- a_out->a_entry >= virtual_offset + a_out->a_text ||
-
+ a_out->a_entry >= (uint64_t)virtual_offset + a_out->a_text ||
/* text and data size must each be page rounded */
- a_out->a_text & PAGE_MASK || a_out->a_data & PAGE_MASK
-
-#ifdef __amd64__
- ||
- /* overflows */
- virtual_offset + a_out->a_text + a_out->a_data + bss_size > UINT_MAX
-#endif
- )
+ (a_out->a_text & PAGE_MASK) != 0 ||
+ (a_out->a_data & PAGE_MASK) != 0 ||
+ /* no overflows */
+ (uint64_t)virtual_offset + a_out->a_text + a_out->a_data +
+ bss_size > UINT_MAX)
return (-1);
/* text + data can't exceed file size */