Compare commits

...
Sign in to create a new pull request.

18 commits

Author SHA1 Message Date
Nick Clifton
10df332a21 Stop a potential call to abort when display the debug information of a corrupt input file. (#2404498) 2025-11-03 13:19:13 +00:00
Nick Clifton
9ae9a31a87 Stop a potential illegal memory access when linking a corrupt input file. (#2404547) 2025-11-03 12:26:50 +00:00
Nick Clifton
8fc43948c9 Stop a potential illegal memory access when linking a corrupt input file. (#2402830) 2025-10-13 11:44:17 +01:00
Nick Clifton
c480582c53 Stop a potential illegal memory access when linking a corrupt input file. (#2402827) 2025-10-10 13:11:19 +01:00
Nick Clifton
e4eb4b56e9 Stop a potential illegal memory access when linking a corrupt input file. (#2400311) 2025-10-03 13:23:42 +01:00
Nick Clifton
5f2f73705b Stop a potential illegal memory access when linking a corrupt input file. (#2400304) 2025-10-02 16:05:03 +01:00
Nick Clifton
990ade43af Stop a potential null pointer dereference when generating sframe information. (#1282126) 2025-07-21 12:04:57 +01:00
Nick Clifton
698ef7dd10 Stop excessive memory allocation when copying corrupt files. (#2379829)
Stop illegal memory access when parsing corrupt files.  (#2379836)
2025-07-14 14:52:00 +01:00
Nick Clifton
f6591b4749 Stop a call to abort in the linker when processing fuzzed input. (#2344837)
Fix an illegal memory access when the linker processed a fuzzed input file.  (#2344835)
2025-02-11 12:50:33 +00:00
Nick Clifton
8db331e7cb Restore the .note.build-id section placement patch.
Resolves: #2331487
2024-12-13 13:41:22 +00:00
Nick Clifton
056dc6ee1d Fix linker testsuite failures 2024-11-27 09:41:44 +00:00
Björn Esser
66262eec5d Fix ppc64 TLS optimization bug with -fno-plt code.
Solution for PR 32387
Resolves: 2324491

Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2024-11-26 12:15:22 +01:00
Nick Clifton
839a6a093e Fix more linker testsuite issues for the RISC-V target. 2024-10-04 18:26:13 +01:00
Nick Clifton
11fc25375a Disable the default enablement of the linker's "-z separate-code" feature for non-x86 architectures. 2024-09-10 10:05:31 +01:00
Nick Clifton
805e066009 Rebase to 2.43.1 release. (#2305399) 2024-09-09 12:55:16 +01:00
Nick Clifton
bb4d098e2f Rebase to 2.43.1 release. (#2305399) 2024-09-09 12:35:41 +01:00
Nick Clifton
36a450d6d2 now with the patch file itself. 2024-08-14 10:29:41 +01:00
Nick Clifton
e92140ca5d Place the .build-id section near the ELF headers. 2024-08-14 10:28:55 +01:00
17 changed files with 1314 additions and 13 deletions

View file

@ -0,0 +1,42 @@
From ea1a0737c7692737a644af0486b71e4a392cbca8 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Mon, 22 Sep 2025 15:20:34 +0800
Subject: [PATCH] elf: Don't read beyond .eh_frame section size
PR ld/33464
* elf-eh-frame.c (_bfd_elf_parse_eh_frame): Don't read beyond
.eh_frame section size.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
bfd/elf-eh-frame.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff -rup binutils-2.43.1.orig/bfd/elf-eh-frame.c binutils-2.43.1/bfd/elf-eh-frame.c
--- binutils-2.43.1.orig/bfd/elf-eh-frame.c 2025-10-03 12:00:40.473590498 +0100
+++ binutils-2.43.1/bfd/elf-eh-frame.c 2025-10-03 12:00:59.521264872 +0100
@@ -734,6 +734,7 @@ _bfd_elf_parse_eh_frame (bfd *abfd, stru
if (hdr_id == 0)
{
unsigned int initial_insn_length;
+ char *null_byte;
/* CIE */
this_inf->cie = 1;
@@ -750,10 +751,13 @@ _bfd_elf_parse_eh_frame (bfd *abfd, stru
REQUIRE (cie->version == 1
|| cie->version == 3
|| cie->version == 4);
- REQUIRE (strlen ((char *) buf) < sizeof (cie->augmentation));
+ null_byte = memchr ((char *) buf, 0, end - buf);
+ REQUIRE (null_byte != NULL);
+ REQUIRE ((size_t) (null_byte - (char *) buf)
+ < sizeof (cie->augmentation));
strcpy (cie->augmentation, (char *) buf);
- buf = (bfd_byte *) strchr ((char *) buf, '\0') + 1;
+ buf = (bfd_byte *) null_byte + 1;
this_inf->u.cie.aug_str_len = buf - start - 1;
ENSURE_NO_RELOCS (buf);
if (buf[0] == 'e' && buf[1] == 'h')

View file

@ -0,0 +1,76 @@
From 9ca499644a21ceb3f946d1c179c38a83be084490 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Thu, 18 Sep 2025 16:59:25 -0700
Subject: [PATCH] elf: Don't match corrupt section header in linker input
Don't swap in nor match corrupt section header in linker input to avoid
linker crash later.
PR ld/33457
* elfcode.h (elf_swap_shdr_in): Changed to return bool. Return
false for corrupt section header in linker input.
(elf_object_p): Reject if elf_swap_shdr_in returns false.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
bfd/elfcode.h | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/bfd/elfcode.h b/bfd/elfcode.h
index 9c65852e103..5224a1abee6 100644
--- a/bfd/elfcode.h
+++ b/bfd/elfcode.h
@@ -311,7 +311,7 @@ elf_swap_ehdr_out (bfd *abfd,
/* Translate an ELF section header table entry in external format into an
ELF section header table entry in internal format. */
-static void
+static bool
elf_swap_shdr_in (bfd *abfd,
const Elf_External_Shdr *src,
Elf_Internal_Shdr *dst)
@@ -341,6 +341,9 @@ elf_swap_shdr_in (bfd *abfd,
{
_bfd_error_handler (_("warning: %pB has a section "
"extending past end of file"), abfd);
+ /* PR ld/33457: Don't match corrupt section header. */
+ if (abfd->is_linker_input)
+ return false;
abfd->read_only = 1;
}
}
@@ -350,6 +353,7 @@ elf_swap_shdr_in (bfd *abfd,
dst->sh_entsize = H_GET_WORD (abfd, src->sh_entsize);
dst->bfd_section = NULL;
dst->contents = NULL;
+ return true;
}
/* Translate an ELF section header table entry in internal format into an
@@ -642,9 +646,9 @@ elf_object_p (bfd *abfd)
/* Read the first section header at index 0, and convert to internal
form. */
- if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr))
+ if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr)
+ || !elf_swap_shdr_in (abfd, &x_shdr, &i_shdr))
goto got_no_match;
- elf_swap_shdr_in (abfd, &x_shdr, &i_shdr);
/* If the section count is zero, the actual count is in the first
section header. */
@@ -730,9 +734,9 @@ elf_object_p (bfd *abfd)
to internal form. */
for (shindex = 1; shindex < i_ehdrp->e_shnum; shindex++)
{
- if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr))
+ if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr)
+ || !elf_swap_shdr_in (abfd, &x_shdr, i_shdrp + shindex))
goto got_no_match;
- elf_swap_shdr_in (abfd, &x_shdr, i_shdrp + shindex);
/* Sanity check sh_link and sh_info. */
if (i_shdrp[shindex].sh_link >= num_sec)
--
2.51.0

View file

@ -0,0 +1,45 @@
From b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Tue, 30 Sep 2025 08:13:56 +0800
Subject: [PATCH] x86: Keep _GLOBAL_OFFSET_TABLE_ for .eh_frame
Since x86 .eh_frame section may reference _GLOBAL_OFFSET_TABLE_, keep
_GLOBAL_OFFSET_TABLE_ if there is dynamic section and the output
.eh_frame section is non-empty.
PR ld/33499
* elfxx-x86.c (_bfd_x86_elf_late_size_sections): Keep
_GLOBAL_OFFSET_TABLE_ if there is dynamic section and the
output .eh_frame section is non-empty.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
bfd/elfxx-x86.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff -rup binutils-with-gold-2.44.orig/bfd/elfxx-x86.c binutils-with-gold-2.44/bfd/elfxx-x86.c
--- binutils-with-gold-2.44.orig/bfd/elfxx-x86.c 2025-10-13 10:42:42.345160623 +0100
+++ binutils-with-gold-2.44/bfd/elfxx-x86.c 2025-10-13 10:42:52.941568120 +0100
@@ -2458,6 +2458,8 @@ _bfd_x86_elf_late_size_sections (bfd *ou
if (htab->elf.sgotplt)
{
+ asection *eh_frame;
+
/* Don't allocate .got.plt section if there are no GOT nor PLT
entries and there is no reference to _GLOBAL_OFFSET_TABLE_. */
if ((htab->elf.hgot == NULL
@@ -2470,7 +2472,11 @@ _bfd_x86_elf_late_size_sections (bfd *ou
&& (htab->elf.iplt == NULL
|| htab->elf.iplt->size == 0)
&& (htab->elf.igotplt == NULL
- || htab->elf.igotplt->size == 0))
+ || htab->elf.igotplt->size == 0)
+ && (!htab->elf.dynamic_sections_created
+ || (eh_frame = bfd_get_section_by_name (output_bfd,
+ ".eh_frame")) == NULL
+ || eh_frame->rawsize == 0))
{
htab->elf.sgotplt->size = 0;
/* Solaris requires to keep _GLOBAL_OFFSET_TABLE_ even if it

View file

@ -0,0 +1,198 @@
From 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Tue, 30 Sep 2025 08:18:29 +0800
Subject: [PATCH] x86: Disallow TLS relocation in non executable section
Since TLS relocations are applied to executable machine instructions,
disallow TLS relocation in non-SHT_PROGBITS, non-SHF_EXECINSTR section.
PR ld/33451
PR ld/33502
* elf32-i386.c (elf_i386_tls_transition): Disallow TLS relocation
in non-SHT_PROGBITS, non-SHF_EXECINSTR section.
(elf_i386_scan_relocs): Likewise.
* elf64-x86-64.c (elf_x86_64_tls_transition): Likewise.
(elf_x86_64_scan_relocs): Likewise.
* elfxx-x86.c (_bfd_x86_elf_link_report_tls_invalid_section_error):
New.
* elfxx-x86.h (_bfd_x86_elf_link_report_tls_invalid_section_error):
Likewise.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
bfd/elf32-i386.c | 19 +++++++++++++++++++
bfd/elf64-x86-64.c | 20 ++++++++++++++++++++
bfd/elfxx-x86.c | 20 ++++++++++++++++++++
bfd/elfxx-x86.h | 4 ++++
4 files changed, 63 insertions(+)
diff -rup binutils-with-gold-2.44.orig/bfd/elf32-i386.c binutils-with-gold-2.44/bfd/elf32-i386.c
--- binutils-with-gold-2.44.orig/bfd/elf32-i386.c 2025-10-10 10:27:34.128669391 +0100
+++ binutils-with-gold-2.44/bfd/elf32-i386.c 2025-10-10 10:27:45.159754790 +0100
@@ -1166,6 +1166,15 @@ elf_i386_tls_transition (struct bfd_link
return true;
}
+ if ((elf_section_type (sec) != SHT_PROGBITS
+ || (sec->flags & SEC_CODE) == 0))
+ {
+ reloc_howto_type *howto = elf_i386_rtype_to_howto (from_type);
+ _bfd_x86_elf_link_report_tls_invalid_section_error
+ (abfd, sec, symtab_hdr, h, sym, howto);
+ return false;
+ }
+
/* Return TRUE if there is no transition. */
if (from_type == to_type)
return true;
@@ -1685,6 +1694,16 @@ elf_i386_scan_relocs (bfd *abfd,
tls_type = GOT_TLS_IE_POS; break;
}
+ if (tls_type >= GOT_TLS_GD
+ && tls_type <= GOT_TLS_GDESC
+ && (elf_section_type (sec) != SHT_PROGBITS
+ || (sec->flags & SEC_CODE) == 0))
+ {
+ _bfd_x86_elf_link_report_tls_invalid_section_error
+ (abfd, sec, symtab_hdr, h, isym, howto);
+ goto error_return;
+ }
+
if (h != NULL)
{
h->got.refcount = 1;
diff -rup binutils-with-gold-2.44.orig/bfd/elf64-x86-64.c binutils-with-gold-2.44/bfd/elf64-x86-64.c
--- binutils-with-gold-2.44.orig/bfd/elf64-x86-64.c 2025-10-10 10:27:34.147669538 +0100
+++ binutils-with-gold-2.44/bfd/elf64-x86-64.c 2025-10-10 10:27:45.161165453 +0100
@@ -1598,6 +1598,16 @@ elf_x86_64_tls_transition (struct bfd_li
return true;
}
+ if ((elf_section_type (sec) != SHT_PROGBITS
+ || (sec->flags & SEC_CODE) == 0))
+ {
+ reloc_howto_type *howto = elf_x86_64_rtype_to_howto (abfd,
+ from_type);
+ _bfd_x86_elf_link_report_tls_invalid_section_error
+ (abfd, sec, symtab_hdr, h, sym, howto);
+ return false;
+ }
+
/* Return TRUE if there is no transition. */
if (from_type == to_type
|| (from_type == R_X86_64_CODE_4_GOTTPOFF
@@ -2351,6 +2361,16 @@ elf_x86_64_scan_relocs (bfd *abfd, struc
break;
}
+ if (tls_type >= GOT_TLS_GD
+ && tls_type <= GOT_TLS_GDESC
+ && (elf_section_type (sec) != SHT_PROGBITS
+ || (sec->flags & SEC_CODE) == 0))
+ {
+ _bfd_x86_elf_link_report_tls_invalid_section_error
+ (abfd, sec, symtab_hdr, h, isym, howto);
+ goto error_return;
+ }
+
if (h != NULL)
{
h->got.refcount = 1;
diff -rup binutils-with-gold-2.44.orig/bfd/elfxx-x86.c binutils-with-gold-2.44/bfd/elfxx-x86.c
--- binutils-with-gold-2.44.orig/bfd/elfxx-x86.c 2025-10-10 10:27:34.204669979 +0100
+++ binutils-with-gold-2.44/bfd/elfxx-x86.c 2025-10-10 10:27:45.161625095 +0100
@@ -3359,6 +3359,26 @@ _bfd_x86_elf_link_report_tls_transition_
bfd_set_error (bfd_error_bad_value);
}
+/* Report TLS invalid section error. */
+
+void
+_bfd_x86_elf_link_report_tls_invalid_section_error
+ (bfd *abfd, asection *sec, Elf_Internal_Shdr *symtab_hdr,
+ struct elf_link_hash_entry *h, Elf_Internal_Sym *sym,
+ reloc_howto_type *howto)
+{
+ const char *name;
+ if (h)
+ name = h->root.root.string;
+ else
+ name = bfd_elf_sym_name (abfd, symtab_hdr, sym, NULL);
+ _bfd_error_handler
+ /* xgettext:c-format */
+ (_("%pB: relocation %s against thread local symbol `%s' in "
+ "invalid section `%pA'"), abfd, howto->name, name, sec);
+ bfd_set_error (bfd_error_bad_value);
+}
+
/* Return TRUE if symbol should be hashed in the `.gnu.hash' section. */
bool
diff -rup binutils-with-gold-2.44.orig/bfd/elfxx-x86.h binutils-with-gold-2.44/bfd/elfxx-x86.h
--- binutils-with-gold-2.44.orig/bfd/elfxx-x86.h 2025-10-10 10:27:34.157669616 +0100
+++ binutils-with-gold-2.44/bfd/elfxx-x86.h 2025-10-10 10:27:45.162048003 +0100
@@ -939,6 +939,10 @@ extern void _bfd_x86_elf_link_report_tls
const Elf_Internal_Rela *, const char *, const char *,
enum elf_x86_tls_error_type);
+extern void _bfd_x86_elf_link_report_tls_invalid_section_error
+ (bfd *, asection *, Elf_Internal_Shdr *, struct elf_link_hash_entry *,
+ Elf_Internal_Sym *, reloc_howto_type *);
+
#define bfd_elf64_mkobject \
_bfd_x86_elf_mkobject
#define bfd_elf32_mkobject \
--- binutils-with-gold-2.44.orig/bfd/elf64-x86-64.c 2025-10-10 10:58:00.684202576 +0100
+++ binutils-with-gold-2.44/bfd/elf64-x86-64.c 2025-10-10 11:01:54.310462809 +0100
@@ -2169,6 +2169,7 @@ elf_x86_64_scan_relocs (bfd *abfd, struc
bool size_reloc;
bool converted_reloc;
bool no_dynreloc;
+ reloc_howto_type *howto;
r_symndx = htab->r_sym (rel->r_info);
r_type = ELF32_R_TYPE (rel->r_info);
@@ -2185,6 +2186,14 @@ elf_x86_64_scan_relocs (bfd *abfd, struc
goto error_return;
}
+ howto = elf_x86_64_rtype_to_howto (abfd, r_type);
+ if (howto == NULL)
+ {
+ _bfd_error_handler (_("%pB: unsupported relocation type %#x"),
+ abfd, r_type);
+ goto error_return;
+ }
+
if (r_symndx < symtab_hdr->sh_info)
{
/* A local symbol. */
--- binutils-with-gold-2.44.orig/bfd/elf32-i386.c 2025-10-10 11:05:23.893062517 +0100
+++ binutils-with-gold-2.44/bfd/elf32-i386.c 2025-10-10 11:06:31.136544677 +0100
@@ -1540,6 +1540,7 @@ elf_i386_scan_relocs (bfd *abfd,
const char *name;
bool size_reloc;
bool no_dynreloc;
+ reloc_howto_type *howto;
r_symndx = ELF32_R_SYM (rel->r_info);
r_type = ELF32_R_TYPE (rel->r_info);
@@ -1556,6 +1557,17 @@ elf_i386_scan_relocs (bfd *abfd,
goto error_return;
}
+ howto = elf_i386_rtype_to_howto (r_type);
+ if (rel->r_offset + bfd_get_reloc_size (howto) > sec->size)
+ {
+ /* xgettext:c-format */
+ _bfd_error_handler
+ (_("%pB: bad reloc offset (%#" PRIx32 " > %#" PRIx32 ") for"
+ " section `%pA'"), abfd, (uint32_t) rel->r_offset,
+ (uint32_t) sec->size, sec);
+ goto error_return;
+ }
+
if (r_symndx < symtab_hdr->sh_info)
{
/* A local symbol. */

View file

@ -0,0 +1,27 @@
From 12ef7d5b7b02d0023db645d86eb9d0797bc747fe Mon Sep 17 00:00:00 2001
From: Nick Clifton <nickc@redhat.com>
Date: Mon, 3 Nov 2025 11:49:02 +0000
Subject: [PATCH] Remove call to abort in the DGB debug format printing code,
thus allowing the display of a fuzzed input file to complete without
triggering an abort.
PR 33448
---
binutils/prdbg.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/binutils/prdbg.c b/binutils/prdbg.c
index c239aeb1a79..5d405c48e3d 100644
--- a/binutils/prdbg.c
+++ b/binutils/prdbg.c
@@ -2449,7 +2449,6 @@ tg_tag_type (void *p, const char *name, unsigned int id,
t = "union class ";
break;
default:
- abort ();
return false;
}
--
2.51.1

View file

@ -0,0 +1,24 @@
From f6b0f53a36820da91eadfa9f466c22f92e4256e0 Mon Sep 17 00:00:00 2001
From: Alan Modra <amodra@gmail.com>
Date: Mon, 3 Nov 2025 09:03:37 +1030
Subject: [PATCH] PR 33455 SEGV in vfinfo at ldmisc.c:527
A reloc howto set up with EMPTY_HOWTO has a NULL name. More than one
place emitting diagnostics assumes a reloc howto won't have a NULL
name.
PR 33455
* coffcode.h (coff_slurp_reloc_table): Don't allow a howto with
a NULL name.
---
--- binutils-2.43.1.orig/bfd/coffcode.h 2025-11-03 11:17:09.463206752 +0000
+++ binutils-2.43.1/bfd/coffcode.h 2025-11-03 11:17:21.031291895 +0000
@@ -5347,7 +5347,7 @@ coff_slurp_reloc_table (bfd * abfd, sec_
RTYPE2HOWTO (cache_ptr, &dst);
#endif /* RELOC_PROCESSING */
- if (cache_ptr->howto == NULL)
+ if (cache_ptr->howto == NULL || cache_ptr->howto->name == NULL)
{
_bfd_error_handler
/* xgettext:c-format */

View file

@ -0,0 +1,38 @@
From 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Sat, 21 Jun 2025 06:36:56 +0800
Subject: [PATCH] objcopy: Don't extend the output section size
Since the output section contents are copied from the input, don't
extend the output section size beyond the input section size.
PR binutils/33049
* objcopy.c (copy_section): Don't extend the output section
size beyond the input section size.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
diff -rup binutils-2.43.1.orig/binutils/objcopy.c binutils-2.43.1/binutils/objcopy.c
--- binutils-2.43.1.orig/binutils/objcopy.c 2025-07-14 13:55:09.475539153 +0100
+++ binutils-2.43.1/binutils/objcopy.c 2025-07-14 13:55:21.639628637 +0100
@@ -4665,6 +4665,7 @@ copy_section (bfd *ibfd, sec_ptr isectio
char *to = (char *) memhunk;
char *end = (char *) memhunk + size;
int i;
+ bfd_size_type memhunk_size = size;
/* If the section address is not exactly divisible by the interleave,
then we must bias the from address. If the copy_byte is less than
@@ -4684,6 +4685,11 @@ copy_section (bfd *ibfd, sec_ptr isectio
}
size = (size + interleave - 1 - copy_byte) / interleave * copy_width;
+
+ /* Don't extend the output section size. */
+ if (size > memhunk_size)
+ size = memhunk_size;
+
osection->lma /= interleave;
if (copy_byte < extra)
osection->lma++;
Only in binutils-2.43.1/binutils: objcopy.c.orig

View file

@ -0,0 +1,48 @@
From 41461010eb7c79fee7a9d5f6209accdaac66cc6b Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Sat, 21 Jun 2025 06:52:00 +0800
Subject: [PATCH] elf: Report corrupted group section
Report corrupted group section instead of trying to recover.
PR binutils/33050
* elf.c (bfd_elf_set_group_contents): Report corrupted group
section.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
diff -rup binutils-2.43.1.orig/bfd/elf.c binutils-2.43.1/bfd/elf.c
--- binutils-2.43.1.orig/bfd/elf.c 2025-07-14 13:55:09.383538476 +0100
+++ binutils-2.43.1/bfd/elf.c 2025-07-14 13:56:50.081279234 +0100
@@ -3931,20 +3931,17 @@ bfd_elf_set_group_contents (bfd *abfd, a
break;
}
- /* We should always get here with loc == sec->contents + 4, but it is
- possible to craft bogus SHT_GROUP sections that will cause segfaults
- in objcopy without checking loc here and in the loop above. */
- if (loc == sec->contents)
- BFD_ASSERT (0);
- else
+ /* We should always get here with loc == sec->contents + 4. Return
+ an error for bogus SHT_GROUP sections. */
+ loc -= 4;
+ if (loc != sec->contents)
{
- loc -= 4;
- if (loc != sec->contents)
- {
- BFD_ASSERT (0);
- memset (sec->contents + 4, 0, loc - sec->contents);
- loc = sec->contents;
- }
+ /* xgettext:c-format */
+ _bfd_error_handler (_("%pB: corrupted group section: `%pA'"),
+ abfd, sec);
+ bfd_set_error (bfd_error_bad_value);
+ *failedptr = true;
+ return;
}
H_PUT_32 (abfd, sec->flags & SEC_LINK_ONCE ? GRP_COMDAT : 0, loc);
Only in binutils-2.43.1/bfd: elf.c.orig

View file

@ -0,0 +1,28 @@
From 75086e9de1707281172cc77f178e7949a4414ed0 Mon Sep 17 00:00:00 2001
From: Nick Clifton <nickc@redhat.com>
Date: Wed, 5 Feb 2025 13:26:51 +0000
Subject: [PATCH] Prevent an abort in the bfd linker when attempting to
generate dynamic relocs for a corrupt input file.
PR 32638
diff -rup binutils.orig/bfd/elf64-x86-64.c binutils-2.43.1/bfd/elf64-x86-64.c
--- binutils.orig/bfd/elf64-x86-64.c 2025-02-11 10:40:56.262887171 +0000
+++ binutils-2.43.1/bfd/elf64-x86-64.c 2025-02-11 10:41:26.312036385 +0000
@@ -4951,6 +4951,15 @@ elf_x86_64_finish_dynamic_symbol (bfd *o
if (generate_dynamic_reloc)
{
+ /* If the relgot section has not been created, then
+ generate an error instead of a reloc. cf PR 32638. */
+ if (relgot == NULL || relgot->size == 0)
+ {
+ info->callbacks->einfo (_("%F%pB: Unable to generate dynamic relocs because a suitable section does not exist\n"),
+ output_bfd);
+ return false;
+ }
+
if (relative_reloc_name != NULL
&& htab->params->report_relative_reloc)
_bfd_x86_elf_link_report_relative_reloc
Only in binutils-2.43.1/bfd: elf64-x86-64.c.orig

View file

@ -0,0 +1,464 @@
commit b425859021d17adf62f06fb904797cf8642986ad
Author: Nick Clifton <nickc@redhat.com>
Date: Wed Feb 5 16:27:38 2025 +0000
Fix another illegal memory access triggered by corrupt ELF input files.
PR 32644
commit 931494c9a89558acb36a03a340c01726545eef24
Author: Nick Clifton <nickc@redhat.com>
Date: Wed Feb 5 15:43:04 2025 +0000
Add even more checks for corrupt input when processing relocations for ELF files.
PR 32643
commit 18cc11a2771d9e40180485da9a4fb660c03efac3
Author: Nick Clifton <nickc@redhat.com>
Date: Wed Feb 5 14:31:10 2025 +0000
Prevent illegal memory access when checking relocs in a corrupt ELF binary.
PR 32641
commit f9978defb6fab0bd8583942d97c112b0932ac814
Author: Nick Clifton <nickc@redhat.com>
Date: Wed Feb 5 11:15:11 2025 +0000
Prevent illegal memory access when indexing into the sym_hashes array of the elf bfd cookie structure.
PR 32636
diff -rup binutils.orig/bfd/elf-bfd.h binutils-2.43.1/bfd/elf-bfd.h
--- binutils.orig/bfd/elf-bfd.h 2025-02-11 10:58:25.223874250 +0000
+++ binutils-2.43.1/bfd/elf-bfd.h 2025-02-11 11:13:12.177965286 +0000
@@ -3147,6 +3147,9 @@ extern bool _bfd_elf_link_mmap_section_c
extern void _bfd_elf_link_munmap_section_contents
(asection *);
+extern struct elf_link_hash_entry * _bfd_elf_get_link_hash_entry
+ (struct elf_link_hash_entry **, unsigned int, Elf_Internal_Shdr *);
+
/* Large common section. */
extern asection _bfd_elf_large_com_section;
diff -rup binutils.orig/bfd/elflink.c binutils-2.43.1/bfd/elflink.c
--- binutils.orig/bfd/elflink.c 2025-02-11 10:58:25.256874290 +0000
+++ binutils-2.43.1/bfd/elflink.c 2025-02-11 11:11:22.536375589 +0000
@@ -96,22 +96,64 @@ _bfd_elf_link_keep_memory (struct bfd_li
return true;
}
-asection *
-_bfd_elf_section_for_symbol (struct elf_reloc_cookie *cookie,
- unsigned long r_symndx,
- bool discard)
+static struct elf_link_hash_entry *
+get_link_hash_entry (struct elf_link_hash_entry ** sym_hashes,
+ unsigned int symndx,
+ unsigned int ext_sym_start)
+{
+ if (sym_hashes == NULL
+ /* Guard against corrupt input. See PR 32636 for an example. */
+ || symndx < ext_sym_start)
+ return NULL;
+
+ struct elf_link_hash_entry *h = sym_hashes[symndx - ext_sym_start];
+
+ /* The hash might be empty. See PR 32641 for an example of this. */
+ if (h == NULL)
+ return NULL;
+
+ while (h->root.type == bfd_link_hash_indirect
+ || h->root.type == bfd_link_hash_warning)
+ h = (struct elf_link_hash_entry *) h->root.u.i.link;
+
+ return h;
+}
+
+struct elf_link_hash_entry *
+_bfd_elf_get_link_hash_entry (struct elf_link_hash_entry ** sym_hashes,
+ unsigned int symndx,
+ Elf_Internal_Shdr * symtab_hdr)
+{
+ if (symtab_hdr == NULL)
+ return NULL;
+
+ return get_link_hash_entry (sym_hashes, symndx, symtab_hdr->sh_info);
+}
+
+static struct elf_link_hash_entry *
+get_ext_sym_hash_from_cookie (struct elf_reloc_cookie *cookie, unsigned long r_symndx)
{
+ if (cookie == NULL || cookie->sym_hashes == NULL)
+ return NULL;
+
if (r_symndx >= cookie->locsymcount
|| ELF_ST_BIND (cookie->locsyms[r_symndx].st_info) != STB_LOCAL)
- {
- struct elf_link_hash_entry *h;
+ return get_link_hash_entry (cookie->sym_hashes, r_symndx, cookie->extsymoff);
- h = cookie->sym_hashes[r_symndx - cookie->extsymoff];
+ return NULL;
+}
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
+asection *
+_bfd_elf_section_for_symbol (struct elf_reloc_cookie *cookie,
+ unsigned long r_symndx,
+ bool discard)
+{
+ struct elf_link_hash_entry *h;
+ h = get_ext_sym_hash_from_cookie (cookie, r_symndx);
+
+ if (h != NULL)
+ {
if ((h->root.type == bfd_link_hash_defined
|| h->root.type == bfd_link_hash_defweak)
&& discarded_section (h->root.u.def.section))
@@ -119,21 +161,20 @@ _bfd_elf_section_for_symbol (struct elf_
else
return NULL;
}
- else
- {
- /* It's not a relocation against a global symbol,
- but it could be a relocation against a local
- symbol for a discarded section. */
- asection *isec;
- Elf_Internal_Sym *isym;
- /* Need to: get the symbol; get the section. */
- isym = &cookie->locsyms[r_symndx];
- isec = bfd_section_from_elf_index (cookie->abfd, isym->st_shndx);
- if (isec != NULL
- && discard ? discarded_section (isec) : 1)
- return isec;
- }
+ /* It's not a relocation against a global symbol,
+ but it could be a relocation against a local
+ symbol for a discarded section. */
+ asection *isec;
+ Elf_Internal_Sym *isym;
+
+ /* Need to: get the symbol; get the section. */
+ isym = &cookie->locsyms[r_symndx];
+ isec = bfd_section_from_elf_index (cookie->abfd, isym->st_shndx);
+ if (isec != NULL
+ && discard ? discarded_section (isec) : 1)
+ return isec;
+
return NULL;
}
@@ -9058,7 +9099,6 @@ set_symbol_value (bfd *bfd_with_globals,
size_t symidx,
bfd_vma val)
{
- struct elf_link_hash_entry **sym_hashes;
struct elf_link_hash_entry *h;
size_t extsymoff = locsymcount;
@@ -9081,12 +9121,12 @@ set_symbol_value (bfd *bfd_with_globals,
/* It is a global symbol: set its link type
to "defined" and give it a value. */
-
- sym_hashes = elf_sym_hashes (bfd_with_globals);
- h = sym_hashes [symidx - extsymoff];
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
+ h = get_link_hash_entry (elf_sym_hashes (bfd_with_globals), symidx, extsymoff);
+ if (h == NULL)
+ {
+ /* FIXMEL What should we do ? */
+ return;
+ }
h->root.type = bfd_link_hash_defined;
h->root.u.def.value = val;
h->root.u.def.section = bfd_abs_section_ptr;
@@ -11568,10 +11608,19 @@ elf_link_input_bfd (struct elf_final_lin
|| (elf_bad_symtab (input_bfd)
&& flinfo->sections[symndx] == NULL))
{
- struct elf_link_hash_entry *h = sym_hashes[symndx - extsymoff];
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
+ struct elf_link_hash_entry *h;
+
+ h = get_link_hash_entry (sym_hashes, symndx, extsymoff);
+ if (h == NULL)
+ {
+ _bfd_error_handler
+ /* xgettext:c-format */
+ (_("error: %pB: unable to create group section symbol"),
+ input_bfd);
+ bfd_set_error (bfd_error_bad_value);
+ return false;
+ }
+
/* Arrange for symbol to be output. */
h->indx = -2;
elf_section_data (osec)->this_hdr.sh_info = -2;
@@ -11706,7 +11755,7 @@ elf_link_input_bfd (struct elf_final_lin
|| (elf_bad_symtab (input_bfd)
&& flinfo->sections[r_symndx] == NULL))
{
- h = sym_hashes[r_symndx - extsymoff];
+ h = get_link_hash_entry (sym_hashes, r_symndx, extsymoff);
/* Badly formatted input files can contain relocs that
reference non-existant symbols. Check here so that
@@ -11715,17 +11764,13 @@ elf_link_input_bfd (struct elf_final_lin
{
_bfd_error_handler
/* xgettext:c-format */
- (_("error: %pB contains a reloc (%#" PRIx64 ") for section %pA "
+ (_("error: %pB contains a reloc (%#" PRIx64 ") for section '%pA' "
"that references a non-existent global symbol"),
input_bfd, (uint64_t) rel->r_info, o);
bfd_set_error (bfd_error_bad_value);
return false;
}
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
-
s_type = h->type;
/* If a plugin symbol is referenced from a non-IR file,
@@ -11941,7 +11986,6 @@ elf_link_input_bfd (struct elf_final_lin
&& flinfo->sections[r_symndx] == NULL))
{
struct elf_link_hash_entry *rh;
- unsigned long indx;
/* This is a reloc against a global symbol. We
have not yet output all the local symbols, so
@@ -11950,11 +11994,13 @@ elf_link_input_bfd (struct elf_final_lin
reloc to point to the global hash table entry
for this symbol. The symbol index is then
set at the end of bfd_elf_final_link. */
- indx = r_symndx - extsymoff;
- rh = elf_sym_hashes (input_bfd)[indx];
- while (rh->root.type == bfd_link_hash_indirect
- || rh->root.type == bfd_link_hash_warning)
- rh = (struct elf_link_hash_entry *) rh->root.u.i.link;
+ rh = get_link_hash_entry (elf_sym_hashes (input_bfd),
+ r_symndx, extsymoff);
+ if (rh == NULL)
+ {
+ /* FIXME: Generate an error ? */
+ continue;
+ }
/* Setting the index to -2 tells
elf_link_output_extsym that this symbol is
@@ -13958,25 +14004,21 @@ _bfd_elf_gc_mark_hook (asection *sec,
struct elf_link_hash_entry *h,
Elf_Internal_Sym *sym)
{
- if (h != NULL)
+ if (h == NULL)
+ return bfd_section_from_elf_index (sec->owner, sym->st_shndx);
+
+ switch (h->root.type)
{
- switch (h->root.type)
- {
- case bfd_link_hash_defined:
- case bfd_link_hash_defweak:
- return h->root.u.def.section;
+ case bfd_link_hash_defined:
+ case bfd_link_hash_defweak:
+ return h->root.u.def.section;
- case bfd_link_hash_common:
- return h->root.u.c.p->section;
+ case bfd_link_hash_common:
+ return h->root.u.c.p->section;
- default:
- break;
- }
+ default:
+ return NULL;
}
- else
- return bfd_section_from_elf_index (sec->owner, sym->st_shndx);
-
- return NULL;
}
/* Return the debug definition section. */
@@ -14025,56 +14067,49 @@ _bfd_elf_gc_mark_rsec (struct bfd_link_i
if (r_symndx == STN_UNDEF)
return NULL;
- if (r_symndx >= cookie->locsymcount
- || ELF_ST_BIND (cookie->locsyms[r_symndx].st_info) != STB_LOCAL)
+ h = get_ext_sym_hash_from_cookie (cookie, r_symndx);
+ if (h == NULL)
{
- bool was_marked;
+ /* A corrup tinput file can lead to a situation where the index
+ does not reference either a local or an external symbol. */
+ if (r_symndx >= cookie->locsymcount)
+ return NULL;
- h = cookie->sym_hashes[r_symndx - cookie->extsymoff];
- if (h == NULL)
- {
- info->callbacks->einfo (_("%F%P: corrupt input: %pB\n"),
- sec->owner);
- return NULL;
- }
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
+ return (*gc_mark_hook) (sec, info, cookie->rel, NULL,
+ &cookie->locsyms[r_symndx]);
+ }
- was_marked = h->mark;
- h->mark = 1;
- /* Keep all aliases of the symbol too. If an object symbol
- needs to be copied into .dynbss then all of its aliases
- should be present as dynamic symbols, not just the one used
- on the copy relocation. */
- hw = h;
- while (hw->is_weakalias)
- {
- hw = hw->u.alias;
- hw->mark = 1;
- }
+ bool was_marked = h->mark;
- if (!was_marked && h->start_stop && !h->root.ldscript_def)
- {
- if (info->start_stop_gc)
- return NULL;
+ h->mark = 1;
+ /* Keep all aliases of the symbol too. If an object symbol
+ needs to be copied into .dynbss then all of its aliases
+ should be present as dynamic symbols, not just the one used
+ on the copy relocation. */
+ hw = h;
+ while (hw->is_weakalias)
+ {
+ hw = hw->u.alias;
+ hw->mark = 1;
+ }
- /* To work around a glibc bug, mark XXX input sections
- when there is a reference to __start_XXX or __stop_XXX
- symbols. */
- else if (start_stop != NULL)
- {
- asection *s = h->u2.start_stop_section;
- *start_stop = true;
- return s;
- }
- }
+ if (!was_marked && h->start_stop && !h->root.ldscript_def)
+ {
+ if (info->start_stop_gc)
+ return NULL;
- return (*gc_mark_hook) (sec, info, cookie->rel, h, NULL);
+ /* To work around a glibc bug, mark XXX input sections
+ when there is a reference to __start_XXX or __stop_XXX
+ symbols. */
+ else if (start_stop != NULL)
+ {
+ asection *s = h->u2.start_stop_section;
+ *start_stop = true;
+ return s;
+ }
}
- return (*gc_mark_hook) (sec, info, cookie->rel, NULL,
- &cookie->locsyms[r_symndx]);
+ return (*gc_mark_hook) (sec, info, cookie->rel, h, NULL);
}
/* COOKIE->rel describes a relocation against section SEC, which is
@@ -15095,17 +15130,12 @@ bfd_elf_reloc_symbol_deleted_p (bfd_vma
if (r_symndx == STN_UNDEF)
return true;
- if (r_symndx >= rcookie->locsymcount
- || ELF_ST_BIND (rcookie->locsyms[r_symndx].st_info) != STB_LOCAL)
- {
- struct elf_link_hash_entry *h;
-
- h = rcookie->sym_hashes[r_symndx - rcookie->extsymoff];
-
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
+ struct elf_link_hash_entry *h;
+ h = get_ext_sym_hash_from_cookie (rcookie, r_symndx);
+
+ if (h != NULL)
+ {
if ((h->root.type == bfd_link_hash_defined
|| h->root.type == bfd_link_hash_defweak)
&& (h->root.u.def.section->owner != rcookie->abfd
@@ -15115,6 +15145,10 @@ bfd_elf_reloc_symbol_deleted_p (bfd_vma
}
else
{
+ if (r_symndx >= rcookie->locsymcount)
+ /* This can happen with corrupt input. */
+ return false;
+
/* It's not a relocation against a global symbol,
but it could be a relocation against a local
symbol for a discarded section. */
diff -rup binutils.orig/bfd/elfxx-x86.c binutils-2.43.1/bfd/elfxx-x86.c
--- binutils.orig/bfd/elfxx-x86.c 2025-02-11 10:58:25.307874350 +0000
+++ binutils-2.43.1/bfd/elfxx-x86.c 2025-02-11 11:15:21.937392450 +0000
@@ -972,15 +972,7 @@ _bfd_x86_elf_check_relocs (bfd *abfd,
goto error_return;
}
- if (r_symndx < symtab_hdr->sh_info)
- h = NULL;
- else
- {
- h = sym_hashes[r_symndx - symtab_hdr->sh_info];
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
- }
+ h = _bfd_elf_get_link_hash_entry (sym_hashes, r_symndx, symtab_hdr);
if (X86_NEED_DYNAMIC_RELOC_TYPE_P (is_x86_64, r_type)
&& NEED_DYNAMIC_RELOCATION_P (is_x86_64, info, true, h, sec,
@@ -1205,10 +1197,12 @@ _bfd_x86_elf_link_relax_section (bfd *ab
else
{
/* Get H and SEC for GENERATE_DYNAMIC_RELOCATION_P below. */
- h = sym_hashes[r_symndx - symtab_hdr->sh_info];
- while (h->root.type == bfd_link_hash_indirect
- || h->root.type == bfd_link_hash_warning)
- h = (struct elf_link_hash_entry *) h->root.u.i.link;
+ h = _bfd_elf_get_link_hash_entry (sym_hashes, r_symndx, symtab_hdr);
+ if (h == NULL)
+ {
+ /* FIXMEL: Issue an error message ? */
+ continue;
+ }
if (h->root.type == bfd_link_hash_defined
|| h->root.type == bfd_link_hash_defweak)

View file

@ -0,0 +1,22 @@
--- binutils.orig/ld/scripttempl/elf.sc 2024-08-14 08:32:58.565047220 +0100
+++ binutils-2.43/ld/scripttempl/elf.sc 2024-08-14 08:34:07.837496401 +0100
@@ -425,7 +425,6 @@ emit_early_ro()
{
cat <<EOF
${INITIAL_READONLY_SECTIONS}
- .note.gnu.build-id ${RELOCATING-0}: { *(.note.gnu.build-id) }
EOF
}
@@ -436,6 +435,11 @@ cat <<EOF
${CREATE_SHLIB-${CREATE_PIE-${RELOCATING+PROVIDE (__executable_start = ${TEXT_START_ADDR}); . = ${TEXT_BASE_ADDRESS};}}}
${CREATE_SHLIB+${RELOCATING+. = ${SHLIB_TEXT_START_ADDR}${SIZEOF_HEADERS_CODE};}}
${CREATE_PIE+${RELOCATING+PROVIDE (__executable_start = ${SHLIB_TEXT_START_ADDR}); . = ${SHLIB_TEXT_START_ADDR}${SIZEOF_HEADERS_CODE};}}
+
+ /* Place build-id as close to the ELF headers as possible. This
+ maximises the chance the build-id will be present in core files,
+ which GDB can use to improve the debug experience. */
+ .note.gnu.build-id ${RELOCATING-0}: { *(.note.gnu.build-id) }
EOF
}

View file

@ -0,0 +1,45 @@
From 1686dc7079f1c03bdaffd2f779b92aa2b7ad97b5 Mon Sep 17 00:00:00 2001
From: Alan Modra <amodra@gmail.com>
Date: Tue, 26 Nov 2024 08:24:19 +1030
Subject: [PATCH] PR32387 ppc64 TLS optimization bug with -fno-plt code
The inline plt code emitted by gcc is incompatible with the
linker/ld.so --tls-get-addr-optimize scheme. This is the runtime
optimisation where the first call to __tls_get_addr results in
__tls_get_addr updating the tls_index pair, then the special linker
stub using that to short-circuit second and subsequent calls for a
given tls symbol. Enabled by default when the linker sees
__tls_get_addr_opt is preseent, and enabled in ld.so when DT_PPC64_OPT
has PPC64_OPT_TLS set. Note that this is distinct from link-time tls
optimisation.
PR 32387
* elf64-ppc.c (ppc64_elf_check_relocs): Disable tls_get_addr_opt
on detecting inline plt calls to __tls_get_addr.
---
bfd/elf64-ppc.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/bfd/elf64-ppc.c b/bfd/elf64-ppc.c
index 9674fcdd6be..f7debc1edbc 100644
--- a/bfd/elf64-ppc.c
+++ b/bfd/elf64-ppc.c
@@ -4915,6 +4915,15 @@ ppc64_elf_check_relocs (bfd *abfd, struct bfd_link_info *info,
tls_type = 0;
switch (r_type)
{
+ case R_PPC64_PLTSEQ:
+ case R_PPC64_PLTSEQ_NOTOC:
+ /* Inline plt call code emitted by gcc doesn't support
+ modifying the tls_index words to short-circuit
+ __tls_get_addr calls. See PR32387. */
+ if (h != NULL && (h == tga || h == dottga))
+ htab->params->tls_get_addr_opt = 0;
+ break;
+
case R_PPC64_TLSGD:
case R_PPC64_TLSLD:
/* These special tls relocs tie a call to __tls_get_addr with
--
2.43.5

View file

@ -147,3 +147,41 @@ diff -rup binutils.orig/ld/testsuite/ld-elf/tls.exp binutils-2.40/ld/testsuite/l
run_ld_link_exec_tests [list \
[list \
"Run pr18808" \
diff -rup binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-01-norelaxgp.d binutils-2.43.50-1f4aee70ed1/ld/testsuite/ld-riscv-elf/pcgp-relax-01-norelaxgp.d
--- binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-01-norelaxgp.d 2024-10-03 15:21:47.926570551 +0100
+++ binutils-2.43.50-1f4aee70ed1/ld/testsuite/ld-riscv-elf/pcgp-relax-01-norelaxgp.d 2024-10-03 15:24:26.152502612 +0100
@@ -8,10 +8,10 @@
Disassembly of section \.text:
0+[0-9a-f]+ <_start>:
-.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a0,a0,\-[0-9]+
+.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a0,a0,.*
.*:[ ]+[0-9a-f]+[ ]+jal[ ]+ra,[0-9a-f]+ <_start>
.*:[ ]+[0-9a-f]+[ ]+auipc[ ]+a1,0x[0-9a-f]+
-.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a1,a1,\-[0-9]+ # [0-9a-f]+ <data_g>
+.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a1,a1,.*
.*:[ ]+[0-9a-f]+[ ]+lui[ ]+a2,0x[0-9a-f]+
.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a2,a2,[0-9]+ # [0-9a-f]+ <data_g>
.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a3,tp,0 # 0 <data_t>
diff -rup binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-01.d binutils-2.43.50-1f4aee70ed1/ld/testsuite/ld-riscv-elf/pcgp-relax-01.d
--- binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-01.d 2024-10-03 15:21:47.926570551 +0100
+++ binutils-2.43.50-1f4aee70ed1/ld/testsuite/ld-riscv-elf/pcgp-relax-01.d 2024-10-03 15:23:54.512530979 +0100
@@ -8,7 +8,7 @@
Disassembly of section \.text:
0+[0-9a-f]+ <_start>:
-.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a0,a0,\-[0-9]+
+.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a0,a0,.*
.*:[ ]+[0-9a-f]+[ ]+jal[ ]+ra,[0-9a-f]+ <_start>
.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a1,gp,\-[0-9]+ # [0-9a-f]+ <data_g>
.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a2,gp,\-[0-9]+ # [0-9a-f]+ <data_g>
diff -rup binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-02.d binutils-2.43.50-1f4aee70ed1/ld/testsuite/ld-riscv-elf/pcgp-relax-02.d
--- binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-02.d 2024-10-03 15:21:47.926570551 +0100
+++ binutils-2.43.50-1f4aee70ed1/ld/testsuite/ld-riscv-elf/pcgp-relax-02.d 2024-10-03 15:25:01.687468496 +0100
@@ -11,5 +11,5 @@ Disassembly of section .text:
[0-9a-f]+ <_start>:
.*:[ ]+[0-9a-f]+[ ]+auipc[ ]+a1.*
.*:[ ]+[0-9a-f]+[ ]+addi[ ]+a0,gp.*<data_a>
-.*:[ ]+[0-9a-f]+[ ]+mv[ ]+a1,a1
+.*:[ ]+[0-9a-f]+[ ]+.*
#pass

View file

@ -0,0 +1,77 @@
From 3602da6fa285d6b22d87bcc39056e919e939ef07 Mon Sep 17 00:00:00 2001
From: Claudiu Zissulescu <claudiu.zissulescu-ianculescu@oracle.com>
Date: Tue, 15 Apr 2025 12:20:40 +0300
Subject: [PATCH] gas: sframe: fix handling of .cfi_def_cfa_register
Fix PR gas/32879 sframe: Assembler internal error when translating
cfi_def_cfa_register
As per the documentation, .cfi_def_cfa_register modifies a rule for
computing CFA; the register is updated, but the offset remains the same.
While translating .cfi_def_cfa_register into SFrame context, we use the
information from last translated FRE to set the CFA offset. However,
there may be cases when the last translated FRE is empty. Use last FRE
only if available.
Signed-off-by: Claudiu Zissulescu <claudiu.zissulescu-ianculescu@oracle.com>
Signed-off-by: Indu Bhagat <indu.bhagat@oracle.com>
---
diff -rupN binutils-2.43.1.orig/gas/gen-sframe.c binutils-2.43.1/gas/gen-sframe.c
--- binutils-2.43.1.orig/gas/gen-sframe.c 2025-07-21 10:18:20.701626832 +0100
+++ binutils-2.43.1/gas/gen-sframe.c 2025-07-21 10:19:04.972504129 +0100
@@ -1051,7 +1051,9 @@ sframe_xlate_do_def_cfa_register (struct
return SFRAME_XLATE_ERR_NOTREPRESENTED; /* Not represented. */
}
sframe_fre_set_cfa_base_reg (cur_fre, cfi_insn->u.ri.reg);
- sframe_fre_set_cfa_offset (cur_fre, last_fre->cfa_offset);
+ if (last_fre)
+ sframe_fre_set_cfa_offset (cur_fre, last_fre->cfa_offset);
+
cur_fre->merge_candidate = false;
return SFRAME_XLATE_OK;
diff -rupN binutils-2.43.1.orig/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.d binutils-2.43.1/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.d
--- binutils-2.43.1.orig/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.d 1970-01-01 01:00:00.000000000 +0100
+++ binutils-2.43.1/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.d 2025-07-21 10:18:35.950185785 +0100
@@ -0,0 +1,21 @@
+#as: --gsframe
+#objdump: --sframe=.sframe
+#name: Check .cfi_def_cfa_register with no previous offset
+#...
+Contents of the SFrame section .sframe:
+
+ Header :
+
+ Version: SFRAME_VERSION_2
+ Flags: NONE
+#? CFA fixed FP offset: \-?\d+
+#? CFA fixed RA offset: \-?\d+
+ Num FDEs: 1
+ Num FREs: 1
+
+ Function Index :
+
+ func idx \[0\]: pc = 0x0, size = 0 bytes
+ STARTPC +CFA +FP +RA +
+ 0+0000 +fp\+8 +u +f +
+#pass
diff -rupN binutils-2.43.1.orig/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.s binutils-2.43.1/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.s
--- binutils-2.43.1.orig/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.s 1970-01-01 01:00:00.000000000 +0100
+++ binutils-2.43.1/gas/testsuite/gas/cfi-sframe/cfi-sframe-x86_64-2.s 2025-07-21 10:18:35.950246411 +0100
@@ -0,0 +1,4 @@
+# Although not a useful construct by itself, ensure graceful handling.
+ .cfi_startproc
+ .cfi_def_cfa_register 6
+ .cfi_endproc
diff -rupN binutils-2.43.1.orig/gas/testsuite/gas/cfi-sframe/cfi-sframe.exp binutils-2.43.1/gas/testsuite/gas/cfi-sframe/cfi-sframe.exp
--- binutils-2.43.1.orig/gas/testsuite/gas/cfi-sframe/cfi-sframe.exp 2025-07-21 10:18:20.756742820 +0100
+++ binutils-2.43.1/gas/testsuite/gas/cfi-sframe/cfi-sframe.exp 2025-07-21 10:19:33.756745567 +0100
@@ -89,6 +89,7 @@ if { [istarget "x86_64-*-*"] && [gas_sfr
if { [gas_x86_64_check] } then {
set ASFLAGS "$ASFLAGS --64"
run_dump_test "cfi-sframe-x86_64-1"
+ run_dump_test "cfi-sframe-x86_64-2"
set ASFLAGS "$old_ASFLAGS"
}
}

View file

@ -1036,3 +1036,18 @@ diff -rup binutils.orig/ld/testsuite/ld-powerpc/tls32no.d binutils-2.42.50-6b19a
.*: (3b de 80 a0|.. 80 de 3b) addi r30,r30,-[0-9]+
.*: (38 7f ff e4|e4 ff 7f 38) addi r3,r31,-28
.*: (48 00 00 6d|6d 00 00 48) bl .*
--- binutils.orig/ld/testsuite/ld-plugin/lto.exp 2024-11-26 16:03:01.214914908 +0000
+++ binutils-2.41/ld/testsuite/ld-plugin/lto.exp 2024-11-26 16:04:39.983307748 +0000
@@ -638,12 +638,6 @@ set lto_run_tests [list \
[list "Run pr20276" \
"-O2 -flto tmpdir/pr20276a.o tmpdir/pr20276b.o" "" \
{dummy.c} "pr20276" "pass.out" "-flto -O2" "c"] \
- [list "Run pr20267a" \
- "-O2 -flto -fcommon tmpdir/pr20267a.o tmpdir/libpr20267a.a" "" \
- {dummy.c} "pr20267a" "pass.out" "-flto -O2 -fcommon" "c"] \
- [list "Run pr20267b" \
- "-O2 -flto -fcommon tmpdir/pr20267a.o tmpdir/libpr20267b.a" "" \
- {dummy.c} "pr20267b" "pass.out" "-flto -O2 -fcommon" "c"] \
[list "Run pr22502" \
"-O2 -flto tmpdir/pr22502a.o tmpdir/pr22502b.o" "" \
{dummy.c} "pr20267" "pass.out" "-flto -O2 -fcommon" "c"] \

View file

@ -6,8 +6,8 @@ Name: binutils%{?_with_debug:-debug}
# A version number of X.XX.90 is a pre-release snapshot.
# The variable %%{source} (see below) should be set to indicate which of these
# origins is being used.
Version: 2.43
Release: 2%{?dist}
Version: 2.43.1
Release: 14%{?dist}
License: GPL-3.0-or-later AND (GPL-3.0-or-later WITH Bison-exception-2.2) AND (LGPL-2.0-or-later WITH GCC-exception-2.0) AND BSD-3-Clause AND GFDL-1.3-or-later AND GPL-2.0-or-later AND LGPL-2.1-or-later AND LGPL-2.0-or-later
URL: https://sourceware.org/binutils
@ -83,10 +83,16 @@ URL: https://sourceware.org/binutils
# configurable in case there is ever a need to disable thread support.
%define enable_threading 1
# Enable the use of separate code and data segments for all architectures,
# not just x86/x86_64.
# Enable the use of separate code and data segments. Whilst potentially
# useful from a security point of view, it is problematic from a file
# size point of view. So for now, only enable it for the i686 and x86_64
# architectures as these are the ones that have the most potential
# vulnerability.
%ifarch %{ix86} x86_64
%define enable_separate_code 1
%else
%define enable_separate_code 0
%endif
# Indicate where the sources come from.
#
@ -294,7 +300,7 @@ Patch17: binutils-riscv-testsuite-fixes.patch
# Lifetime: Fixed in 2.44 (maybe)
Patch18: binutils-gold-pack-relative-relocs.patch
# Purpose: Let the gold lihnker ignore --error-execstack and --error-rwx-segments.
# Purpose: Let the gold linker ignore --error-execstack and --error-rwx-segments.
# Lifetime: Fixed in 2.44 (maybe)
Patch19: binutils-gold-ignore-execstack-error.patch
@ -302,9 +308,66 @@ Patch19: binutils-gold-ignore-execstack-error.patch
# Lifetime: Fixed in 2.44
Patch20: binutils-fix-ar-test.patch
# Purpose: Fix PR 31956 and BZ 2301454.
# Lifetime: Fixed in 2.43.1 ?
Patch21: binutils-LTO-restore-wrapper-symbol.patch
# Purpose: Fix ppc64 TLS optimization bug with -fno-plt code.
# Lifetime: Fixed in 2.44
Patch21: binutils-ppc64-TLS-no_plt-optimization-bug.patch
# Purpose: Place the .build-id section near the ELF headers
# Lifetime: Fixed in 2.44
Patch22: binutils-linker-script-build-id-placement.patch
# Purpose: Stops a call to abort in the linker when processing fuzzed input.
# Lifetime: Fixed in 2.45
Patch23: binutils-ld-gen-dynamic-relocs.patch
# Purpose: Stops a call to abort in the linker when processing fuzzed input.
# Lifetime: Fixed in 2.45
Patch24: binutils-ld-sym-hashes.patch
# Purpose: Stops excessive memory use when copying corrupt files.
# Lifetime: Fixed in 2.45
Patch25: binutils-CVE-2025-7545.patch
# Purpose: Stops illegal memory access when parsing corrupt files.
# Lifetime: Fixed in 2.45
Patch26: binutils-CVE-2025-7546.patch
# Purpose: Stops a potential null pointer dereference when generating sframe
# information in the assembler.
# Lifetime: Fixed in 2.45
Patch27: binutils-sframe-PR32879.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33457
# Lifetime: Fixed in 2.46
Patch28: binutils-CVE-2025-11083.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33464
# Lifetime: Fixed in 2.46
Patch29: binutils-CVE-2025-11082.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33451
# Lifetime: Fixed in 2.46
Patch30: binutils-CVE-2025-11495.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33499
# Lifetime: Fixed in 2.46
Patch31: binutils-CVE-2025-11494.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33455
# Lifetime: Fixed in 2.46
Patch32: binutils-CVE-2025-11840.patch
# Purpose: Stops a potential call to abort when displaying the debug info
# of a corrupt input file. PR 33448
# Lifetime: Fixed in 2.46
Patch33: binutils-CVE-2025-11839.patch
#----------------------------------------------------------------------------
# Purpose: Suppress the x86 linker's p_align-1 tests due to kernel bug on CentOS-10
# Lifetime: TEMPORARY
@ -694,7 +757,10 @@ compute_global_configuration()
%if %{enable_separate_code}
CARGS="$CARGS --enable-separate-code=yes"
CARGS="$CARGS --enable-rosegment=yes"
CARGS="$CARGS --enable-rosegment=yes"
%else
CARGS="$CARGS --enable-separate-code=no"
CARGS="$CARGS --enable-rosegment=no"
%endif
%if %{enable_threading}
@ -762,7 +828,7 @@ run_target_configuration()
# Extra targets to build along with the native one.
#
# BZ 1920373: Enable PEP support for all targets as the PERF package's
# testsuite expects to be able to read PE format files ragrdless of
# testsuite expects to be able to read PE format files regardless of
# the host's architecture.
#
# Also enable the BPF target so that strip will work on BPF files.
@ -1031,7 +1097,7 @@ install_binutils()
%make_install DESTDIR=%{buildroot} MAKEINFO=true
%endif
# Rebuild the static libiaries with -fPIC.
# Rebuild the static libraries with -fPIC.
# It would be nice to build the static libraries with -fno-lto so that
# they can be used by programs that are built with a different version
# of GCC from the one used to build the libraries, but this will trigger
@ -1361,6 +1427,54 @@ exit 0
#----------------------------------------------------------------------------
%changelog
* Mon Oct 13 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-14
- Stop a potential call to abort when display the debug information of a corrupt input file. (#2404498)
* Mon Oct 13 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-13
- Stop a potential illegal memory access when linking a corrupt input file. (#2404547)
* Mon Oct 13 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-12
- Stop a potential illegal memory access when linking a corrupt input file. (#2402830)
* Fri Oct 10 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-11
- Stop a potential illegal memory access when linking a corrupt input file. (#2402827)
* Fri Oct 03 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-10
- Stop a potential illegal memory access when linking a corrupt input file. (#2400311)
* Thu Oct 02 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-9
- Stop a potential illegal memory access when linking a corrupt input file. (#2400304)
* Mon Jul 21 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-8
- Stop a potential null pointer dereference when generating sframe information. (#1282126)
* Mon Jul 14 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-7
- Stop excessive memory allocation when copying corrupt files. (#2379829)
- Stop illegal memory access when parsing corrupt files. (#2379836)
* Tue Feb 11 2025 Nick Clifton <nickc@redhat.com> - 2.43.1-6
- Stop a call to abort in the linker when processing fuzzed input. (#2344837)
- Fix an illegal memory access when the linker processed a fuzzed input file. (#2344835)
* Fri Dec 13 2024 Björn Esser <besser82@fedoraproject.org> - 2.43.1-5
- Restore the .note.build-id section placement patch. (#2331487)
* Tue Nov 26 2024 Björn Esser <besser82@fedoraproject.org> - 2.43.1-4
- Fix ppc64 TLS optimization bug with -fno-plt code. (#2324491)
* Fri Oct 04 2024 Nick Clifton <nickc@redhat.com> - 2.43.1-3
- Fix more linker testsuite issues for the RISC-V target.
* Mon Sep 09 2024 Nick Clifton <nickc@redhat.com> - 2.43.1-2
- Disable the default enablement of the linker's "-z separate-code" feature for non-x86 architectures.
* Mon Sep 09 2024 Nick Clifton <nickc@redhat.com> - 2.43.1-1
- Rebase to 2.43.1 release. (#2305399)
- Retire: binutils-LTO-restore-wrapper-symbol.patch
* Wed Aug 14 2024 Nick Clifton <nickc@redhat.com> - 2.43-3
- Place the .build-id section near the ELF headers.
* Mon Aug 05 2024 Nick Clifton <nickc@redhat.com> - 2.43-2
- Use correct fix for BZ 2301454.

View file

@ -1,2 +1,2 @@
SHA512 (binutils-2.43.tar.xz) = 93e063163e54d6a6ee2bd48dc754270bf757a3635b49a702ed6b310e929e94063958512d191e66beaf44275f7ea60865dbde138b624626739679fcc306b133bb
SHA512 (binutils-2.43.1.tar.xz) = 20977ad17729141a2c26d358628f44a0944b84dcfefdec2ba029c2d02f40dfc41cc91c0631044560d2bd6f9a51e1f15846b4b311befbe14f1239f14ff7d57824
SHA512 (binutils-2.19.50.0.1-output-format.sed) = 2f8686b0c8af13c98cda056824c2820416f6e2d003f70b78ccf5314525b9ee3684d421dfa83e638a2d42d06ea4d4bdaf5226b64d6ec26f7ff59c44ffb2a23dd2