From patchwork Tue May 9 07:48:58 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alan Modra X-Patchwork-Id: 91405 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2694451vqo; Tue, 9 May 2023 00:49:19 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ7bachEJ/mjccht176ijHkHM0er8HKqEoeC5yzfPbKXYpj5/TIWPWw6vYCXLqfTXoUBOVOV X-Received: by 2002:a50:eb48:0:b0:50b:c479:fed7 with SMTP id z8-20020a50eb48000000b0050bc479fed7mr10959761edp.21.1683618559544; Tue, 09 May 2023 00:49:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1683618559; cv=none; d=google.com; s=arc-20160816; b=wbu5VYG3dmfEgbwbsJSH+8iaz88kv9U9pIYYFDua/khSFrP9iKinGSoeXzC7ViCSIF 5DJExhHcmHW9bkF9MZie6LqE7fihc8mkTRl/vKjNvvMEyo0QtB8b59Rsqsw2KoElaV09 xpmG4WlfSpNW4DK/GHPXYwIO4aqhIFdBEQxJXik4QmyWljZU9+iJAmbp/99m6rAZGYmf Y9qWM+XPy0cBg+19LG2UGN2YP9T4w5Px/eed1PQ1T/HrlEY3xLwF5x2MHvjgXnKP7V2+ gf7QV8GKBbdBvG4Zk3yo9I2fZDM5BLlOjMPtyaZLLxrXeyergl1FBt/Ves1Pu9iZUci3 wPGw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:reply-to:from:list-subscribe:list-help:list-post :list-archive:list-unsubscribe:list-id:precedence :content-disposition:mime-version:message-id:subject:to:date :dmarc-filter:delivered-to:dkim-signature:dkim-filter; bh=UVeOATDbJ3UhAhNMzsUpd4zPGFEzgep/E4CawNRRmq8=; b=jBQh9JecWDOJpqZRYzrYJDm3cuomht1SVdos0CfvzNkc9IQW9ut0N+Ar9NPJoUjbjP h2HURd0LwcegCWDq7I4Z/yjG6WXNh0BqsDg7LfCjLeIM2pQXanIvMG0dUwVclzgZU1gS L6r0bqoB+6DBh2DNu8G2iduuC/K6FhhN0E+YOp2dUXQN2mKxSPMTgikDccLFoAnLwkvO vHVdgip3IYdqYHnLQnqVYc2VKwAaKB2yNi7r33Ltq1BeIIRcI4jOgcbtd/oVi4QrR6d6 8sJR2u3icKKssn+W0tPpq85SVzdifHyntSGvsjgYZK+LGLgXsG7kOWL2DVh/uDzYx7vN oVvg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=qXuvv8yt; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from sourceware.org (server2.sourceware.org. [2620:52:3:1:0:246e:9693:128c]) by mx.google.com with ESMTPS id r23-20020a056402019700b00509d1c11c4csi745391edv.686.2023.05.09.00.49.19 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 09 May 2023 00:49:19 -0700 (PDT) Received-SPF: pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) client-ip=2620:52:3:1:0:246e:9693:128c; Authentication-Results: mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=qXuvv8yt; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 2620:52:3:1:0:246e:9693:128c as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id F3F0E385700F for ; Tue, 9 May 2023 07:49:13 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org F3F0E385700F DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sourceware.org; s=default; t=1683618554; bh=UVeOATDbJ3UhAhNMzsUpd4zPGFEzgep/E4CawNRRmq8=; h=Date:To:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post: List-Help:List-Subscribe:From:Reply-To:From; b=qXuvv8ytSEVjXGcNvODd1NMNs11p6cWtOA1CcmfrtKvrWK1aXvhCo+2vobC44CVIz 5eEGjz4sZ29D+FGB6gtfCC3kwoAT0fv7Pdk/Id+J3e6e46b5VbY/ygv8lonw+gZBFx atJ6lGTxThUmTsvlVjFvkI6Frg/Gl2iZsaAKISUo= X-Original-To: binutils@sourceware.org Delivered-To: binutils@sourceware.org Received: from mail-pg1-x52c.google.com (mail-pg1-x52c.google.com [IPv6:2607:f8b0:4864:20::52c]) by sourceware.org (Postfix) with ESMTPS id 55A7F3857835 for ; Tue, 9 May 2023 07:49:05 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 55A7F3857835 Received: by mail-pg1-x52c.google.com with SMTP id 41be03b00d2f7-52cbd7e73d2so3131790a12.3 for ; Tue, 09 May 2023 00:49:05 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1683618542; x=1686210542; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=UVeOATDbJ3UhAhNMzsUpd4zPGFEzgep/E4CawNRRmq8=; b=MIYtD7dWosdDxNBro9F4QdpDyspHFcLLUvFhLC6DNj2FnbpA99022G1nZWESJTOnaw E6sSTKGFB6FVfPgbn3eP4bK8TSMBTy07Y5IR26GDyjbfWPuF3aTl+PGYe9D4iXnuXgmo 3tfvACT5+g2JMZhcBImXm8ZrYgE+LJeBl4x9V3btMJXUjana3UjwIglTlVvHGSYUMxlR EzKj9SxnAuOCC4LZHZ7qTacoZT+cIHxHYm0SsytqppI4kk0RhhmGD1tC+L1Vaebd6vRb 6qtNDSy9OxumjRWDdpbHHJ7duhfFE/FVSStk8S8W8p6RRTz48R+xPYKWM6D6wBG1V3Ol OljQ== X-Gm-Message-State: AC+VfDxNJf9yEHly5xisEakNgp8qaM7D7s/ijtUWxubWUuFN5RKPiT3/ 24Wo3VPJ9Yhsm9zUeoOn6UgHdb+SMCQ= X-Received: by 2002:a17:903:2308:b0:19c:fc41:2dfd with SMTP id d8-20020a170903230800b0019cfc412dfdmr15719049plh.29.1683618542596; Tue, 09 May 2023 00:49:02 -0700 (PDT) Received: from squeak.grove.modra.org ([2406:3400:51d:8cc0:d355:ce8c:3fd4:7c01]) by smtp.gmail.com with ESMTPSA id jb17-20020a170903259100b001a27e5ee634sm850925plb.33.2023.05.09.00.49.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 09 May 2023 00:49:01 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id 2A6101142C09; Tue, 9 May 2023 17:18:58 +0930 (ACST) Date: Tue, 9 May 2023 17:18:58 +0930 To: binutils@sourceware.org Subject: stack overflow in debug_write_type Message-ID: MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-3034.3 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Patchwork-Original-From: Alan Modra via Binutils From: Alan Modra Reply-To: Alan Modra Errors-To: binutils-bounces+ouuuleilei=gmail.com@sourceware.org Sender: "Binutils" X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1765402015074693292?= X-GMAIL-MSGID: =?utf-8?q?1765402015074693292?= Another fuzzer attack. This one was a "set" with elements using an indirect type pointing back at the set. The existing recursion check only prevented simple recursion. * debug.c (struct debug_type_s): Add mark. (debug_write_type): Set mark and check before recursing into indirect types. diff --git a/binutils/debug.c b/binutils/debug.c index 53b45879e00..5cc77f74906 100644 --- a/binutils/debug.c +++ b/binutils/debug.c @@ -105,6 +105,8 @@ struct debug_type_s enum debug_type_kind kind; /* Size of type (0 if not known). */ unsigned int size; + /* Used by debug_write to stop DEBUG_KIND_INDIRECT infinite recursion. */ + unsigned int mark; /* Type which is a pointer to this type. */ debug_type pointer; /* Tagged union with additional information about the type. */ @@ -2422,6 +2424,9 @@ debug_write_type (struct debug_handle *info, if (type == DEBUG_TYPE_NULL) return (*fns->empty_type) (fhandle); + /* Mark the type so that we don't define a type in terms of itself. */ + type->mark = info->mark; + /* If we have a name for this type, just output it. We only output typedef names after they have been defined. We output type tags whenever we are not actually defining them. */ @@ -2485,7 +2490,7 @@ debug_write_type (struct debug_handle *info, return false; case DEBUG_KIND_INDIRECT: /* Prevent infinite recursion. */ - if (*type->u.kindirect->slot == type) + if ((*type->u.kindirect->slot)->mark == info->mark) return (*fns->empty_type) (fhandle); return debug_write_type (info, fns, fhandle, *type->u.kindirect->slot, name);