binutils/binutils-CVE-2025-7546.patch
Nick Clifton 698ef7dd10 Stop excessive memory allocation when copying corrupt files. (#2379829)
Stop illegal memory access when parsing corrupt files.  (#2379836)
2025-07-14 14:52:00 +01:00

48 lines
1.6 KiB
Diff

From 41461010eb7c79fee7a9d5f6209accdaac66cc6b Mon Sep 17 00:00:00 2001
From: "H.J. Lu" <hjl.tools@gmail.com>
Date: Sat, 21 Jun 2025 06:52:00 +0800
Subject: [PATCH] elf: Report corrupted group section
Report corrupted group section instead of trying to recover.
PR binutils/33050
* elf.c (bfd_elf_set_group_contents): Report corrupted group
section.
Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
---
diff -rup binutils-2.43.1.orig/bfd/elf.c binutils-2.43.1/bfd/elf.c
--- binutils-2.43.1.orig/bfd/elf.c 2025-07-14 13:55:09.383538476 +0100
+++ binutils-2.43.1/bfd/elf.c 2025-07-14 13:56:50.081279234 +0100
@@ -3931,20 +3931,17 @@ bfd_elf_set_group_contents (bfd *abfd, a
break;
}
- /* We should always get here with loc == sec->contents + 4, but it is
- possible to craft bogus SHT_GROUP sections that will cause segfaults
- in objcopy without checking loc here and in the loop above. */
- if (loc == sec->contents)
- BFD_ASSERT (0);
- else
+ /* We should always get here with loc == sec->contents + 4. Return
+ an error for bogus SHT_GROUP sections. */
+ loc -= 4;
+ if (loc != sec->contents)
{
- loc -= 4;
- if (loc != sec->contents)
- {
- BFD_ASSERT (0);
- memset (sec->contents + 4, 0, loc - sec->contents);
- loc = sec->contents;
- }
+ /* xgettext:c-format */
+ _bfd_error_handler (_("%pB: corrupted group section: `%pA'"),
+ abfd, sec);
+ bfd_set_error (bfd_error_bad_value);
+ *failedptr = true;
+ return;
}
H_PUT_32 (abfd, sec->flags & SEC_LINK_ONCE ? GRP_COMDAT : 0, loc);
Only in binutils-2.43.1/bfd: elf.c.orig