From b1034b86023672e6750da49b01a7d429cd8339d0 Mon Sep 17 00:00:00 2001 From: Xavier Del Campo Romero Date: Sat, 15 Nov 2025 18:50:55 +0100 Subject: Check memory linear accesses are within bounds WebAssembly defines how many pages of linear memory are owned by the instance on startup. This limit can then be bumped via the grow_memory operator. Therefore, accesses outside the defined bounds are considered an exception. --- src/interp/linear/load.c | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) (limited to 'src/interp/linear/load.c') diff --git a/src/interp/linear/load.c b/src/interp/linear/load.c index afc6154..38294c4 100644 --- a/src/interp/linear/load.c +++ b/src/interp/linear/load.c @@ -9,6 +9,7 @@ #include #include +#include #include #include #include @@ -17,7 +18,21 @@ enum nw_state nwp_linear_load(struct nw_interp *const i, struct nw_sm_io *const io, const unsigned long offset) { const struct nw_interp_cfg *const cfg = &i->cfg; - const enum nw_state n = nwp_mem_load(&cfg->linear, io, offset, cfg->user); + enum nw_state n; + + if (nwp_linear_check(i, offset, io->n)) + { + static const char *const exc = "out-of-bounds read access to " + "linear memory"; + +#ifdef NW_LOG + nwp_log("%s, addr=%#lx, sz=%#lx\n", exc, offset, io->n); +#endif + i->exception = exc; + return NW_FATAL; + } + + n = nwp_mem_load(&cfg->linear, io, offset, cfg->user); if (n == NW_FATAL) { -- cgit v1.2.3