yann@570: Original patch from gentoo: gentoo/src/patchsets/gdb/6.7.1/80_all_gdb-6.5-dwarf-stack-overflow.patch yann@570: -= BEGIN original header =- yann@570: http://bugs.gentoo.org/144833 yann@570: yann@570: for gdb/ChangeLog: yann@570: 2006-08-22 Will Drewry yann@570: Tavis Ormandy yann@570: yann@570: * dwarf2read.c (decode_locdesc): Enforce location description stack yann@570: boundaries. yann@570: * dwarfread.c (locval): Likewise. yann@570: yann@570: -= END original header =- yann@570: diff -durN gdb-6.7.1.orig/gdb/dwarf2read.c gdb-6.7.1/gdb/dwarf2read.c yann@570: --- gdb-6.7.1.orig/gdb/dwarf2read.c 2007-09-05 02:51:48.000000000 +0200 yann@570: +++ gdb-6.7.1/gdb/dwarf2read.c 2008-06-17 23:27:46.000000000 +0200 yann@570: @@ -9061,8 +9061,7 @@ yann@570: callers will only want a very basic result and this can become a yann@570: complaint. yann@570: yann@570: - Note that stack[0] is unused except as a default error return. yann@570: - Note that stack overflow is not yet handled. */ yann@570: + Note that stack[0] is unused except as a default error return. */ yann@570: yann@570: static CORE_ADDR yann@570: decode_locdesc (struct dwarf_block *blk, struct dwarf2_cu *cu) yann@570: @@ -9079,7 +9078,7 @@ yann@570: yann@570: i = 0; yann@570: stacki = 0; yann@570: - stack[stacki] = 0; yann@570: + stack[++stacki] = 0; yann@570: yann@570: while (i < size) yann@570: { yann@570: @@ -9261,6 +9260,16 @@ yann@570: dwarf_stack_op_name (op)); yann@570: return (stack[stacki]); yann@570: } yann@570: + /* Enforce maximum stack depth of size-1 to avoid ++stacki writing yann@570: + outside of the allocated space. Also enforce minimum > 0. yann@570: + -- wad@google.com 14 Aug 2006 */ yann@570: + if (stacki >= sizeof (stack) / sizeof (*stack) - 1) yann@570: + internal_error (__FILE__, __LINE__, yann@570: + _("location description stack too deep: %d"), yann@570: + stacki); yann@570: + if (stacki <= 0) yann@570: + internal_error (__FILE__, __LINE__, yann@570: + _("location description stack too shallow")); yann@570: } yann@570: return (stack[stacki]); yann@570: }