From: Nick Clifton Date: Wed, 20 Jun 2018 15:30:05 +0000 (+0100) Subject: Fix potential illegal memroy access when using a build-id note with a negative size. X-Git-Url: https://git.libre-soc.org/?a=commitdiff_plain;h=6077de0645ce12a9c4e99f8839a846b42a535b0a;p=binutils-gdb.git Fix potential illegal memroy access when using a build-id note with a negative size. PR 23316 * opncls.c (get_build_id): Check for a negative or excessive data size in the build-id note. --- diff --git a/bfd/ChangeLog b/bfd/ChangeLog index 110115c438e..bdbdf69d5aa 100644 --- a/bfd/ChangeLog +++ b/bfd/ChangeLog @@ -10,6 +10,12 @@ BFD_RELOC_AARCH64_TLSLE_LDST64_TPREL_LO12_NC, BFD_RELOC_AARCH64_TLSLE_LDST8_TPREL_LO12_NC. +2018-06-20 Nick Clifton + + PR 23316 + * opncls.c (get_build_id): Check for a negative or excessive data + size in the build-id note. + 2018-06-20 Nick Clifton PR 23299 diff --git a/bfd/opncls.c b/bfd/opncls.c index 16b568c8ab2..e27504545cf 100644 --- a/bfd/opncls.c +++ b/bfd/opncls.c @@ -1877,10 +1877,11 @@ get_build_id (bfd *abfd) inote.descdata = inote.namedata + BFD_ALIGN (inote.namesz, 4); /* FIXME: Should we check for extra notes in this section ? */ - if (inote.descsz == 0 + if (inote.descsz <= 0 || inote.type != NT_GNU_BUILD_ID || inote.namesz != 4 /* sizeof "GNU" */ || strncmp (inote.namedata, "GNU", 4) != 0 + || inote.descsz > 0x7ffffffe || size < (12 + BFD_ALIGN (inote.namesz, 4) + inote.descsz)) { free (contents);