From f00901886d0acb7a4d4b177a5cabe8bd9ca2307b Mon Sep 17 00:00:00 2001 From: Alan Modra Date: Thu, 19 Dec 2019 15:38:39 +1030 Subject: [PATCH] vax decoding of indexed addressing mode This patch prevents print_insn_mode recursing into another index mode byte, which if repeated enough times will overflow private.the_buffer and scribble over other memory. * vax-dis.c (print_insn_mode): Stop index mode recursion. --- opcodes/ChangeLog | 4 ++++ opcodes/vax-dis.c | 14 ++++++++++++-- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/opcodes/ChangeLog b/opcodes/ChangeLog index 0ace940313a..49b94e3a34e 100644 --- a/opcodes/ChangeLog +++ b/opcodes/ChangeLog @@ -1,3 +1,7 @@ +2019-12-19 Alan Modra + + * vax-dis.c (print_insn_mode): Stop index mode recursion. + 2019-12-19 Dr N.W. Filardo PR 25277 diff --git a/opcodes/vax-dis.c b/opcodes/vax-dis.c index 0b331412d39..f88001584a4 100644 --- a/opcodes/vax-dis.c +++ b/opcodes/vax-dis.c @@ -240,8 +240,18 @@ print_insn_mode (const char *d, (*info->fprintf_func) (info->stream, "$0x%x", mode); break; case 0x40: /* Index: base-addr[Rn] */ - p += print_insn_mode (d, size, p0 + 1, addr + 1, info); - (*info->fprintf_func) (info->stream, "[%s]", reg_names[reg]); + { + unsigned char *q = p0 + 1; + unsigned char nextmode = NEXTBYTE (q); + if (nextmode < 0x60 || nextmode == 0x8f) + /* Literal, index, register, or immediate is invalid. In + particular don't recurse into another index mode which + might overflow the_buffer. */ + (*info->fprintf_func) (info->stream, "[invalid base]"); + else + p += print_insn_mode (d, size, p0 + 1, addr + 1, info); + (*info->fprintf_func) (info->stream, "[%s]", reg_names[reg]); + } break; case 0x50: /* Register: Rn */ (*info->fprintf_func) (info->stream, "%s", reg_names[reg]); -- 2.30.2