3 ms·
For the simplified example given in the CVE: word* target = segmentStart + farPointer.offset; if (target < segmentStart || target >= segmentEnd) { thro
by madmoose 9y ago
For the simplified example given in the CVE:
word* target = segmentStart + farPointer.offset;
if (target < segmentStart || target >= segmentEnd) {
throwBoundsError();
}
doSomething(*target);
Here's how I'd do it. (Caveat emptor, not knowing all the relevant types in the example, etc.)
size_t segmentLength = segmentEnd - segmentStart;
if (farPointer.offset >= segmentLength) {
throwBoundsError();
}
word* target = segmentStart + farPointer.offset;
doSomething(*target);
In general you can never compare pointers unless they point into the same array or object. In fact, even creating an invalid pointer is UB, you don't event have to compare or dereference it.