Fix crash with invalid bytecode vectors

* src/lread.c (read_vector): If the vector is to short to be for
bytecodes don’t do bytecode processing for it, as the processing
might run past the end of the vector.
This commit is contained in:
Paul Eggert 2020-05-27 09:50:07 -07:00
parent 9d11f127f1
commit dcd96745b0

View file

@ -3844,6 +3844,10 @@ read_vector (Lisp_Object readcharfun, bool bytecodeflag)
ptrdiff_t size = list_length (tem);
Lisp_Object vector = make_nil_vector (size);
/* Avoid accessing past the end of a vector if the vector is too
small to be valid for bytecode. */
bytecodeflag &= COMPILED_STACK_DEPTH < size;
Lisp_Object *ptr = XVECTOR (vector)->contents;
for (ptrdiff_t i = 0; i < size; i++)
{