git: f15642e24db7 - main - imgact_aout: Widen the overflow checks in exec_aout_imgact()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 18:58:39 UTC
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=f15642e24db7d16c63ce484924d9075926dbf58a

commit f15642e24db7d16c63ce484924d9075926dbf58a
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-29 18:56:22 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 18:56:22 +0000

    imgact_aout: Widen the overflow checks in exec_aout_imgact()
    
    I suspect this overflow check isn't needed at all, at least today, since
    vm_map_insert() will detect wraparound when it creates segments (and
    even a check against UINT_MAX is too loose, since the max user address
    is AOUT32_USRSTACK == 0xbfc00000).  But if we're going to keep this
    check, there doesn't seem to be any downside to applying it on all
    platforms, before exec_new_vmspace() tears down the current vmspace.
    
    Reported by:    Muhammed Sariyildiz <asiyee994@gmail.com>
    Reviewed by:    kib
    MFC after:      2 weeks
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D60027
---
 sys/kern/imgact_aout.c | 16 ++++++----------
 1 file changed, 6 insertions(+), 10 deletions(-)

diff --git a/sys/kern/imgact_aout.c b/sys/kern/imgact_aout.c
index 9978c74f0dee..86ee8f6913b9 100644
--- a/sys/kern/imgact_aout.c
+++ b/sys/kern/imgact_aout.c
@@ -236,17 +236,13 @@ exec_aout_imgact(struct image_params *imgp)
 	 */
 	if (/* entry point must lay with text region */
 	    a_out->a_entry < virtual_offset ||
-	    a_out->a_entry >= virtual_offset + a_out->a_text ||
-
+	    a_out->a_entry >= (uint64_t)virtual_offset + a_out->a_text ||
 	    /* text and data size must each be page rounded */
-	    a_out->a_text & PAGE_MASK || a_out->a_data & PAGE_MASK
-
-#ifdef __amd64__
-	    ||
-	    /* overflows */
-	    virtual_offset + a_out->a_text + a_out->a_data + bss_size > UINT_MAX
-#endif
-	    )
+	    (a_out->a_text & PAGE_MASK) != 0 ||
+	    (a_out->a_data & PAGE_MASK) != 0 ||
+	    /* no overflows */
+	    (uint64_t)virtual_offset + a_out->a_text + a_out->a_data +
+	    bss_size > UINT_MAX)
 		return (-1);
 
 	/* text + data can't exceed file size */