Compare commits

...
Sign in to create a new pull request.

8 commits

Author SHA1 Message Date
Nick Clifton
4c95d31d7d Add support for zstd compression. (#2454341) 2026-04-08 11:33:24 +01:00
Nick Clifton
1ff5036d07 Remove experimental Risc-V patch added with -2 revision. 2026-01-15 13:06:38 +00:00
Nick Clifton
dc4df4e96a Fix Risc-V related test failures caused by -2 revision. 2026-01-09 16:56:20 +00:00
Nick Clifton
90c9453706 Change Risc-V assembler to default to disabling relaxation. 2026-01-05 13:40:20 +00:00
Nick Clifton
bb5d7aeac8 Fix sources 2025-11-12 12:16:09 +00:00
Nick Clifton
9dac73ea8c Rebase to the binutils 2.45.1 release. 2025-11-12 12:15:23 +00:00
Nick Clifton
0c47e9d593 Stop a potential illegal memory access when linking a corrupt input file. (CVE-2025-11082)
Stop a potential illegal memory access when linking a corrupt input file.  (CVE-2025-11083)
2025-10-03 13:27:10 +01:00
Nick Clifton
2752f0f412 Enhance the riscv-64 zicfilp-unlabeled-plt test to cope with larger offsets. 2025-09-12 10:46:20 +01:00
5 changed files with 183 additions and 3 deletions

View file

@ -0,0 +1,45 @@
From ea1a0737c7692737a644af0486b71e4a392cbca8 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Mon, 22 Sep 2025 15:20:34 +0800
Subject: [PATCH] elf: Don't read beyond .eh_frame section size
PR ld/33464
* elf-eh-frame.c (_bfd_elf_parse_eh_frame): Don't read beyond
.eh_frame section size.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
bfd/elf-eh-frame.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/bfd/elf-eh-frame.c b/bfd/elf-eh-frame.c
index dc0d2e097f5..30bb313489c 100644
--- a/bfd/elf-eh-frame.c
+++ b/bfd/elf-eh-frame.c
@@ -737,6 +737,7 @@ _bfd_elf_parse_eh_frame (bfd *abfd, struct bfd_link_info *info,
if (hdr_id == 0)
{
unsigned int initial_insn_length;
+ char *null_byte;
/* CIE */
this_inf->cie = 1;
@@ -753,10 +754,13 @@ _bfd_elf_parse_eh_frame (bfd *abfd, struct bfd_link_info *info,
REQUIRE (cie->version == 1
|| cie->version == 3
|| cie->version == 4);
- REQUIRE (strlen ((char *) buf) < sizeof (cie->augmentation));
+ null_byte = memchr ((char *) buf, 0, end - buf);
+ REQUIRE (null_byte != NULL);
+ REQUIRE ((size_t) (null_byte - (char *) buf)
+ < sizeof (cie->augmentation));
strcpy (cie->augmentation, (char *) buf);
- buf = (bfd_byte *) strchr ((char *) buf, '\0') + 1;
+ buf = (bfd_byte *) null_byte + 1;
this_inf->u.cie.aug_str_len = buf - start - 1;
ENSURE_NO_RELOCS (buf);
if (buf[0] == 'e' && buf[1] == 'h')
--
2.51.0

View file

@ -0,0 +1,76 @@
From 9ca499644a21ceb3f946d1c179c38a83be084490 Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Thu, 18 Sep 2025 16:59:25 -0700
Subject: [PATCH] elf: Don't match corrupt section header in linker input
Don't swap in nor match corrupt section header in linker input to avoid
linker crash later.
PR ld/33457
* elfcode.h (elf_swap_shdr_in): Changed to return bool. Return
false for corrupt section header in linker input.
(elf_object_p): Reject if elf_swap_shdr_in returns false.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
bfd/elfcode.h | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/bfd/elfcode.h b/bfd/elfcode.h
index 9c65852e103..5224a1abee6 100644
--- a/bfd/elfcode.h
+++ b/bfd/elfcode.h
@@ -311,7 +311,7 @@ elf_swap_ehdr_out (bfd *abfd,
/* Translate an ELF section header table entry in external format into an
ELF section header table entry in internal format. */
-static void
+static bool
elf_swap_shdr_in (bfd *abfd,
const Elf_External_Shdr *src,
Elf_Internal_Shdr *dst)
@@ -341,6 +341,9 @@ elf_swap_shdr_in (bfd *abfd,
{
_bfd_error_handler (_("warning: %pB has a section "
"extending past end of file"), abfd);
+ /* PR ld/33457: Don't match corrupt section header. */
+ if (abfd->is_linker_input)
+ return false;
abfd->read_only = 1;
}
}
@@ -350,6 +353,7 @@ elf_swap_shdr_in (bfd *abfd,
dst->sh_entsize = H_GET_WORD (abfd, src->sh_entsize);
dst->bfd_section = NULL;
dst->contents = NULL;
+ return true;
}
/* Translate an ELF section header table entry in internal format into an
@@ -642,9 +646,9 @@ elf_object_p (bfd *abfd)
/* Read the first section header at index 0, and convert to internal
form. */
- if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr))
+ if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr)
+ || !elf_swap_shdr_in (abfd, &x_shdr, &i_shdr))
goto got_no_match;
- elf_swap_shdr_in (abfd, &x_shdr, &i_shdr);
/* If the section count is zero, the actual count is in the first
section header. */
@@ -730,9 +734,9 @@ elf_object_p (bfd *abfd)
to internal form. */
for (shindex = 1; shindex < i_ehdrp->e_shnum; shindex++)
{
- if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr))
+ if (bfd_read (&x_shdr, sizeof x_shdr, abfd) != sizeof (x_shdr)
+ || !elf_swap_shdr_in (abfd, &x_shdr, i_shdrp + shindex))
goto got_no_match;
- elf_swap_shdr_in (abfd, &x_shdr, i_shdrp + shindex);
/* Sanity check sh_link and sh_info. */
if (i_shdrp[shindex].sh_link >= num_sec)
--
2.51.0

View file

@ -172,3 +172,13 @@ diff -rup binutils.orig/ld/testsuite/ld-riscv-elf/pcgp-relax-02.d binutils-2.43.
-.*:[ ]+[0-9a-f]+[ ]+mv[ ]+a1,a1
+.*:[ ]+[0-9a-f]+[ ]+.*
#pass
--- binutils-with-gold-2.45.50-79b2b564fec.orig/ld/testsuite/ld-riscv-elf/zicfilp-unlabeled-plt.d 2025-09-09 15:52:30.684689609 +0100
+++ binutils-with-gold-2.45.50-79b2b564fec/ld/testsuite/ld-riscv-elf/zicfilp-unlabeled-plt.d 2025-09-09 15:53:12.837859447 +0100
@@ -30,6 +30,6 @@ Disassembly of section \.plt:
[0-9a-f]+ <bar@plt>:
.*:[ ]+[0-9a-f]+[ ]+lpad[ ]+0x0
-.*:[ ]+[0-9a-f]+[ ]+auipc[ ]+t3,0x1
+.*:[ ]+[0-9a-f]+[ ]+auipc[ ]+t3,0x[0-9a-f]+
.*:[ ]+[0-9a-f]+[ ]+ld[ ]+t3,[0-9]+\(t3\) # [0-9a-f]+ <bar>
.*:[ ]+[0-9a-f]+[ ]+jalr[ ]+t1,t3

View file

@ -6,8 +6,8 @@ Name: binutils%{?_with_debug:-debug}
# A version number of X.XX.90 is a pre-release snapshot.
# The variable %%{source} (see below) should be set to indicate which of these
# origins is being used.
Version: 2.45
Release: 1%{?dist}
Version: 2.45.1
Release: 5%{?dist}
License: GPL-3.0-or-later AND (GPL-3.0-or-later WITH Bison-exception-2.2) AND (LGPL-2.0-or-later WITH GCC-exception-2.0) AND BSD-3-Clause AND GFDL-1.3-or-later AND GPL-2.0-or-later AND LGPL-2.1-or-later AND LGPL-2.0-or-later
URL: https://sourceware.org/binutils
@ -27,6 +27,7 @@ URL: https://sourceware.org/binutils
# --without systemzlib Use the binutils version of zlib. Default is to use the system version.
# --without testsuite Do not run the testsuite. Default is to run it.
# --without xxhash Do not link against the xxhash library.
# --without zstd Do not link against the zstd library.
# Other configuration options can be set by modifying the following defines.
@ -141,6 +142,8 @@ URL: https://sourceware.org/binutils
%bcond_without testsuite
# Default: Use the xxhash-devel library.
%bcond_without xxhash
# Default: Use the libztsd-devel library.
%bcond_without zstd
# Note - in the future the gold linker may become deprecated.
%ifnarch riscv64
@ -327,6 +330,16 @@ Patch18: binutils-fix-ar-test.patch
# Lifetime: Fixed in 2.45
Patch19: binutils-aarch64-small-plt0.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33457
# Lifetime: Fixed in 2.46
Patch20: binutils-CVE-2025-11083.patch
# Purpose: Stops a potential illegal memory access when linking a corrupt
# input file. PR 33464
# Lifetime: Fixed in 2.46
Patch21: binutils-CVE-2025-11082.patch
#----------------------------------------------------------------------------
# Purpose: Suppress the x86 linker's p_align-1 tests due to kernel bug on CentOS-10
@ -407,6 +420,10 @@ BuildRequires: elfutils-debuginfod-client-devel
BuildRequires: xxhash-devel
%endif
%if %{with zstd}
BuildRequires: libzstd-devel
%endif
Requires(post): %{_sbindir}/alternatives
Requires(preun): %{_sbindir}/alternatives
# We also need rm.
@ -698,6 +715,14 @@ compute_global_configuration()
%if %{with xxhash}
CARGS="$CARGS --with-xxhash=yes"
%else
CARGS="$CARGS --with-xxhash=no"
%endif
%if %{with zstd}
CARGS="$CARGS --with-zstd=yes"
%else
CARGS="$CARGS --with-zstd=no"
%endif
%if %{default_compress_debug}
@ -1462,6 +1487,30 @@ exit 0
#----------------------------------------------------------------------------
%changelog
* Wed Apr 08 2026 Nick Clifton <nickc@redhat.com> - 2.45.1-5
- Add support for zstd compression. (#2454341)
* Thu Jan 15 2026 Nick Clifton <nickc@redhat.com> - 2.45.1-4
- Remove experimental Risc-V patch added with -2 revision.
* Fri Jan 09 2026 Nick Clifton <nickc@redhat.com> - 2.45.1-3
- Fix Risc-V related test failures caused by previous patch.
* Mon Jan 05 2026 Nick Clifton <nickc@redhat.com> - 2.45.1-2
- Change Risc-V assembler to default to disabling relaxation.
* Wed Nov 12 2025 Nick Clifton <nickc@redhat.com> - 2.45.1-1
- Rebase to the 2.45.1 release.
* Fri Oct 03 2025 Nick Clifton <nickc@redhat.com> - 2.45-4
- Stop a potential illegal memory access when linking a corrupt input file. (CVE-2025-11082)
* Thu Oct 02 2025 Nick Clifton <nickc@redhat.com> - 2.45-3
- Stop a potential illegal memory access when linking a corrupt input file. (CVE-2025-11083)
* Fri Sep 12 2025 Nick Clifton <nickc@redhat.com> - 2.45-2
- Enhance the riscv-64 zicfilp-unlabeled-plt test to cope with larger offsets.
* Mon Jul 28 2025 Nick Clifton <nickc@redhat.com> - 2.45-1
- Rebase to official GNU Binutils 2.45 release.

View file

@ -1,3 +1,3 @@
SHA512 (binutils-2.45.tar.xz) = c7b10a7466d9fd398d7a0b3f2a43318432668d714f2ec70069a31bdc93c86d28e0fe83792195727167743707fbae45337c0873a0786416db53bbf22860c16ce7
SHA512 (binutils-2.45.1.tar.xz) = ea030419eba387579ab717be7e3223fc99e93b586860b06003c12489f93441640d4082736f76aa5e98233db4f46e232f536a45e471486de1f5b64e1b827c167e
SHA512 (binutils-2.19.50.0.1-output-format.sed) = 2f8686b0c8af13c98cda056824c2820416f6e2d003f70b78ccf5314525b9ee3684d421dfa83e638a2d42d06ea4d4bdaf5226b64d6ec26f7ff59c44ffb2a23dd2
SHA512 (binutils-with-gold-2.44.50-21e608528c3.tar.xz) = 5d8d4123ca290893ce20b73ad94263102e602bfc0d3f3b9412f5dd769c5bd44a1330b954b012442f8f2dcee6392992b44218d6d200b986a10359bb11e8ac5c3b