fix possible segfault in hook del (#691) (#697)

This commit is contained in:
Ryan Hileman 2016-12-21 11:50:40 -05:00 committed by Nguyen Anh Quynh
parent b19f1607c6
commit 19b92a4a7e

16
uc.c
View file

@ -1069,20 +1069,20 @@ uc_err uc_hook_add(uc_engine *uc, uc_hook *hh, int type, void *callback,
UNICORN_EXPORT UNICORN_EXPORT
uc_err uc_hook_del(uc_engine *uc, uc_hook hh) uc_err uc_hook_del(uc_engine *uc, uc_hook hh)
{ {
int i = 0; int i;
struct hook *hook = (struct hook *)hh; struct hook *hook = (struct hook *)hh;
int type = hook->type; // we can't dereference hook->type if hook is invalid
// so for now we need to iterate over all possible types to remove the hook
while ((type >> i) > 0 && i < UC_HOOK_MAX) { // which is less efficient
if ((type >> i) & 1) { // an optimization would be to align the hook pointer
if (list_remove(&uc->hook[i], (void *)hh)) { // and store the type mask in the hook pointer.
for (i = 0; i < UC_HOOK_MAX; i++) {
if (list_remove(&uc->hook[i], (void *)hook)) {
if (--hook->refs == 0) { if (--hook->refs == 0) {
free(hook); free(hook);
} }
} }
} }
i++;
}
return UC_ERR_OK; return UC_ERR_OK;
} }