[binutils-gdb] mep disassembler buffer overflow

Alan Modra via Binutils-cvs <[email protected]> Wed, 17 Jun 2026 23:55:55 +0000 (GMT)
Newsgroups gmane.comp.gnu.binutils.cvs
Message-ID <[email protected]>
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=70f2a72f53388a289c17bbb120e268e649b71ab3

commit 70f2a72f53388a289c17bbb120e268e649b71ab3
Author: Alan Modra <[email protected]>
Date:   Thu Jun 18 09:20:56 2026 +0930

    mep disassembler buffer overflow
    
    mep_examine_vliw64_insns uses a buffer of size 4 to read 8 bytes.
    Fix that, and tidy other places obscuring the code by using a macro to
    size buffers.
    
    cpu/
            * mep.opc (mep_print_vliw_insns): Delete commented out insnbuf.
            (mep_examine_vliw32_insns): Don't use CGEN_MAX_INSN_SIZE in
            buf size.  Set buflength using sizeof.  Delete comment.
            (mep_examine_vliw64_insns): Likewise.
            (mep_examine_ivc2_insns): Likewise.
    opcodes/
            * mep-dis.c: Regenerate.

Diff:
---
 cpu/mep.opc       | 11 +++++------
 opcodes/mep-dis.c | 11 +++++------
 2 files changed, 10 insertions(+), 12 deletions(-)

diff --git a/cpu/mep.opc b/cpu/mep.opc
index 33dd63b4b9d..032906cadf6 100644
--- a/cpu/mep.opc
+++ b/cpu/mep.opc
@@ -937,7 +937,6 @@ mep_print_vliw_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info,
 {
   int i;
   int status = 0;
-  /* char insnbuf[CGEN_MAX_INSN_SIZE]; */
   bfd_byte insnbuf[64];
 
   /* If corelength > 0 then there is a core insn present. It
@@ -1100,7 +1099,7 @@ mep_examine_vliw32_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   int corebuflength;
   int cop1buflength;
   int cop2buflength;
-  bfd_byte buf[CGEN_MAX_INSN_SIZE];
+  bfd_byte buf[4];
   char indicator16[1];
   char indicatorcop32[2];
 
@@ -1109,7 +1108,7 @@ mep_examine_vliw32_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   cop2buflength = 0;
 
   /* Read in 32 bits.  */
-  buflength = 4; /* VLIW insn spans 4 bytes.  */
+  buflength = sizeof (buf);
   status = (*info->read_memory_func) (pc, buf, buflength, info);
 
   if (status != 0)
@@ -1175,7 +1174,7 @@ mep_examine_vliw64_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   int corebuflength;
   int cop1buflength;
   int cop2buflength;
-  bfd_byte buf[CGEN_MAX_INSN_SIZE];
+  bfd_byte buf[8];
   char indicator16[1];
   char indicator64[4];
 
@@ -1184,7 +1183,7 @@ mep_examine_vliw64_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   cop2buflength = 0;
 
   /* Read in 64 bits.  */
-  buflength = 8; /* VLIW insn spans 8 bytes.  */
+  buflength = sizeof (buf);
   status = (*info->read_memory_func) (pc, buf, buflength, info);
 
   if (status != 0)
@@ -1341,7 +1340,7 @@ mep_examine_ivc2_insns (CGEN_CPU_DESC cd ATTRIBUTE_UNUSED, bfd_vma pc ATTRIBUTE_
   int e;
 
   /* Read in 64 bits.  */
-  buflength = 8; /* VLIW insn spans 8 bytes.  */
+  buflength = sizeof (buf);
   status = (*info->read_memory_func) (pc, buf, buflength, info);
 
   if (status != 0)
diff --git a/opcodes/mep-dis.c b/opcodes/mep-dis.c
index b18454d6156..864511aeca9 100644
--- a/opcodes/mep-dis.c
+++ b/opcodes/mep-dis.c
@@ -132,7 +132,6 @@ mep_print_vliw_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info,
 {
   int i;
   int status = 0;
-  /* char insnbuf[CGEN_MAX_INSN_SIZE]; */
   bfd_byte insnbuf[64];
 
   /* If corelength > 0 then there is a core insn present. It
@@ -295,7 +294,7 @@ mep_examine_vliw32_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   int corebuflength;
   int cop1buflength;
   int cop2buflength;
-  bfd_byte buf[CGEN_MAX_INSN_SIZE];
+  bfd_byte buf[4];
   char indicator16[1];
   char indicatorcop32[2];
 
@@ -304,7 +303,7 @@ mep_examine_vliw32_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   cop2buflength = 0;
 
   /* Read in 32 bits.  */
-  buflength = 4; /* VLIW insn spans 4 bytes.  */
+  buflength = sizeof (buf);
   status = (*info->read_memory_func) (pc, buf, buflength, info);
 
   if (status != 0)
@@ -370,7 +369,7 @@ mep_examine_vliw64_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   int corebuflength;
   int cop1buflength;
   int cop2buflength;
-  bfd_byte buf[CGEN_MAX_INSN_SIZE];
+  bfd_byte buf[8];
   char indicator16[1];
   char indicator64[4];
 
@@ -379,7 +378,7 @@ mep_examine_vliw64_insns (CGEN_CPU_DESC cd, bfd_vma pc, disassemble_info *info)
   cop2buflength = 0;
 
   /* Read in 64 bits.  */
-  buflength = 8; /* VLIW insn spans 8 bytes.  */
+  buflength = sizeof (buf);
   status = (*info->read_memory_func) (pc, buf, buflength, info);
 
   if (status != 0)
@@ -536,7 +535,7 @@ mep_examine_ivc2_insns (CGEN_CPU_DESC cd ATTRIBUTE_UNUSED, bfd_vma pc ATTRIBUTE_
   int e;
 
   /* Read in 64 bits.  */
-  buflength = 8; /* VLIW insn spans 8 bytes.  */
+  buflength = sizeof (buf);
   status = (*info->read_memory_func) (pc, buf, buflength, info);
 
   if (status != 0)