-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[CVE-2017-11861] [ChakraCore] Chakra JIT - Incorrect integer overflow…
… check in Lowerer::LowerBoundCheck - Google, Inc. Math on IntConstType should be bounded by IRType of the Opnd. In case of Lowerer::LowerBoundCheck, it ended up that the IntConstOpnd is a TyInt32 and the overflow leads to bad bound check being emitted. For this I added a new IntConstMath class which takes an IRType as a parameter and validates that the result can be represented by that IRType.
- Loading branch information
1 parent
c1bdfff
commit 85d42e7
Showing
13 changed files
with
144 additions
and
34 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,84 @@ | ||
//------------------------------------------------------------------------------------------------------- | ||
// Copyright (C) Microsoft Corporation and contributors. All rights reserved. | ||
// Licensed under the MIT license. See LICENSE.txt file in the project root for full license information. | ||
//------------------------------------------------------------------------------------------------------- | ||
|
||
#include "Backend.h" | ||
|
||
bool IntConstMath::IsValid(IntConstType val, IRType type) | ||
{ | ||
switch (type) | ||
{ | ||
#if TARGET_32 | ||
case TyInt32: | ||
case TyUint32: | ||
CompileAssert(sizeof(IntConstType) == sizeof(int32)); | ||
return true; | ||
#elif TARGET_64 | ||
case TyInt32: | ||
case TyUint32: | ||
return Math::FitsInDWord(val); | ||
case TyInt64: | ||
case TyUint64: | ||
CompileAssert(sizeof(IntConstType) == sizeof(int64)); | ||
return true; | ||
#endif | ||
default: | ||
Assert(UNREACHED); | ||
return false; | ||
} | ||
} | ||
|
||
bool IntConstMath::Add(IntConstType left, IntConstType right, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Add(left, right, result); | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Sub(IntConstType left, IntConstType right, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Sub(left, right, result); | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Mul(IntConstType left, IntConstType right, IRType type, IntConstType * result) | ||
{ | ||
#if TARGET_32 | ||
bool overflowed = Int32Math::Mul(left, right, result); | ||
CompileAssert(sizeof(IntConstType) == sizeof(int32)); | ||
#elif TARGET_64 | ||
bool overflowed = Int64Math::Mul(left, right, result); | ||
CompileAssert(sizeof(IntConstType) == sizeof(int64)); | ||
#endif | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Div(IntConstType left, IntConstType right, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Div(left, right, result); | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Mod(IntConstType left, IntConstType right, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Mod(left, right, result); | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Dec(IntConstType val, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Dec(val, result); | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Inc(IntConstType val, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Inc(val, result); | ||
return overflowed || !IsValid(*result, type); | ||
} | ||
|
||
bool IntConstMath::Neg(IntConstType val, IRType type, IntConstType * result) | ||
{ | ||
bool overflowed = IntMathCommon<IntConstType>::Neg(val, result); | ||
return overflowed || !IsValid(*result, type); | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
//------------------------------------------------------------------------------------------------------- | ||
// Copyright (C) Microsoft Corporation and contributors. All rights reserved. | ||
// Licensed under the MIT license. See LICENSE.txt file in the project root for full license information. | ||
//------------------------------------------------------------------------------------------------------- | ||
|
||
#pragma once | ||
|
||
class IntConstMath | ||
{ | ||
public: | ||
static bool Add(IntConstType left, IntConstType right, IRType type, IntConstType * result); | ||
static bool Sub(IntConstType left, IntConstType right, IRType type, IntConstType * result); | ||
static bool Mul(IntConstType left, IntConstType right, IRType type, IntConstType * result); | ||
static bool Div(IntConstType left, IntConstType right, IRType type, IntConstType * result); | ||
static bool Mod(IntConstType left, IntConstType right, IRType type, IntConstType * result); | ||
|
||
static bool Dec(IntConstType val, IRType type, IntConstType * result); | ||
static bool Inc(IntConstType val, IRType type, IntConstType * result); | ||
static bool Neg(IntConstType val, IRType type, IntConstType * result); | ||
|
||
private: | ||
static bool IsValid(IntConstType val, IRType type); | ||
}; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.