+2021-05-10 Alan Modra <amodra@gmail.com>
+
+ * dwarf.c (SAFE_BYTE_GET): Check bounds by subtracting amount from
+ END rather than adding amount to PTR.
+ (SAFE_SIGNED_BYTE_GET, SAFE_BYTE_GET64): Likewise.
+
2021-05-09 Alan Modra <amodra@gmail.com>
* objcopy.c (eq_string): Delete.
amount, (int) sizeof (VAL)); \
amount = sizeof (VAL); \
} \
- if (((PTR) + amount) >= (END)) \
+ if ((PTR) >= (END) - amount) \
{ \
if ((PTR) < (END)) \
amount = (END) - (PTR); \
do \
{ \
unsigned int amount = (AMOUNT); \
- if (((PTR) + amount) >= (END)) \
+ if ((PTR) >= (END) - amount) \
{ \
if ((PTR) < (END)) \
amount = (END) - (PTR); \
#define SAFE_BYTE_GET64(PTR, HIGH, LOW, END) \
do \
{ \
- if (((PTR) + 8) <= (END)) \
+ if ((PTR) <= (END) - 8) \
{ \
byte_get_64 ((PTR), (HIGH), (LOW)); \
} \