From patchwork Mon Jun 5 07:20:34 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alan Modra X-Patchwork-Id: 103136 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:994d:0:b0:3d9:f83d:47d9 with SMTP id k13csp2504784vqr; Mon, 5 Jun 2023 00:21:07 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ5897C+io5xhu+jKPbHfuxCgjFKg1qpR3gv52iifrjTbQNGKiCcQ/13X+omKIL7j84jyLtR X-Received: by 2002:a17:907:720c:b0:94e:d951:d4e7 with SMTP id dr12-20020a170907720c00b0094ed951d4e7mr6534364ejc.59.1685949666948; Mon, 05 Jun 2023 00:21:06 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1685949666; cv=none; d=google.com; s=arc-20160816; b=MmoJBeYz4JJQzgLW5lQnwN2XD9mWXnKzuALnoWG1/2NQhduiQ+E8SKRgStS8krXu01 r58UpKUJAbvA2CPtqWZ97ga47Oh4TRHGlcqaEd/d8EyUu83c5Vzr8+CcVTwwHvbfRebd K6Kyi4PGz4NewwYoi+LFJBC5sWPQWE0ykzaAZAAM53r30Gt817YNvGO0l5fWNxEjm/J7 rTFNLvIArYRB652huH/u883HXhTJVddmIxWJyEAaXd7FKn2V0iryimWgOhHlxcyoilIH rSbDN16gMFB+4aRKTh9fvgvtvPNS9qd6YA6x5XCgW0RRw0U+D63Evc33bAqve/SqeIwP cfYw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:reply-to:from:list-subscribe:list-help:list-post :list-archive:list-unsubscribe:list-id:precedence :content-disposition:mime-version:message-id:subject:to:date :dmarc-filter:delivered-to:dkim-signature:dkim-filter; bh=by0LTAXAu1hkUBAM3TMXeH/vtyDo7eqak1bsGCngcxs=; b=OvbatS9kXQbyBRlUCuHxxo0q+fJEj6HtQK4Np2sDg+i85oN8UPWWTQeKY0RCbJk0k8 URHvcKysqYAEibxhxy/VXirGVE0/kuulhl1A58NZW4Y2dhycvpTVZPQbxsoizQo0MFNr LVnREA1jL1sWdN+kErceQ0//R/BtFXpFyEyCt33dKREQJayecI/ECVCbApHm+6KAzEsF 8U7k24n/Zq2thafN1iztzH0x+3SyZuRuMk5cGLwS7Az/2F/vgpguNNl8NMmwU4dDBxH7 Nocr2CMBO5lgEws6pA3NHSChcZ/v1J187yTxqiUOxF4cC62+O5BDkojUo38fozeCHUXk ve5w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=jueeB5OD; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 8.43.85.97 as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from sourceware.org ([8.43.85.97]) by mx.google.com with ESMTPS id ho36-20020a1709070ea400b00977cba9a8a1si2456476ejc.733.2023.06.05.00.21.06 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 05 Jun 2023 00:21:06 -0700 (PDT) Received-SPF: pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 8.43.85.97 as permitted sender) client-ip=8.43.85.97; Authentication-Results: mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=jueeB5OD; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 8.43.85.97 as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id D56F4385B527 for ; Mon, 5 Jun 2023 07:21:05 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org D56F4385B527 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sourceware.org; s=default; t=1685949665; bh=by0LTAXAu1hkUBAM3TMXeH/vtyDo7eqak1bsGCngcxs=; h=Date:To:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post: List-Help:List-Subscribe:From:Reply-To:From; b=jueeB5ODE10+qMX82am/tIuCJeimknHFtnVITjYXTBozo+SRUL/VUfTAaCNfsAjSl VK/WA64Qe2osZlZ+un0AVd8R/N0t/bfvHcw39NRQMI/IMWaTXBfW4WJ5GEh4WopeL9 x5Ce92tfHrDnJ7FoCvuLYbq3p+SkZ54v1hMfNJMU= X-Original-To: binutils@sourceware.org Delivered-To: binutils@sourceware.org Received: from mail-ot1-x336.google.com (mail-ot1-x336.google.com [IPv6:2607:f8b0:4864:20::336]) by sourceware.org (Postfix) with ESMTPS id C61E2385B534 for ; Mon, 5 Jun 2023 07:20:40 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org C61E2385B534 Received: by mail-ot1-x336.google.com with SMTP id 46e09a7af769-6b2041315a5so272188a34.0 for ; Mon, 05 Jun 2023 00:20:40 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1685949639; x=1688541639; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=by0LTAXAu1hkUBAM3TMXeH/vtyDo7eqak1bsGCngcxs=; b=fP7f2dwG2iTfVgx5BTskWVxCyiPCfPxaysA6FUi/7UO0daZCMCylRg4D5OYITBTOTL WtGgf5Ez8odf7eVBEHEREpzSH9m+oI24bq9Q4wUFfmX3f05334Dh4MMchibnFsh4TXr9 LDIauMEfwzgH3j7uHoaJ8NOJ0HwbPZLTW8lLWVGKExnRhsWEAASGYoAsVppJBR8fc9mA 6A/qXT3l5x/wdJbI9/xRgpt7zv42B3BNZOtyVMQlsVV38Jol+TcKT81z3jdoJn86hkKn GLAYpDddttj6uvPLP8ld2Goteaj627zOGpSG+aUQBzGipZp+I4HzoH0aPERsFbHmk0Ik BOJg== X-Gm-Message-State: AC+VfDwMmLB8ey26sZx9xBDckZ+pyQQr+lOhDD3JP+tZMLyT0+oHz7/K ogbSN4aOdh/AhuGiQ72SulDxJjbHiW0= X-Received: by 2002:a9d:7857:0:b0:6af:e87e:aa5e with SMTP id c23-20020a9d7857000000b006afe87eaa5emr9302187otm.12.1685949639569; Mon, 05 Jun 2023 00:20:39 -0700 (PDT) Received: from squeak.grove.modra.org ([2406:3400:51d:8cc0:4d08:cebd:d73f:b794]) by smtp.gmail.com with ESMTPSA id j3-20020a62e903000000b0063f2a5a59d1sm4534330pfh.190.2023.06.05.00.20.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 05 Jun 2023 00:20:38 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id 0A33A1142CA1; Mon, 5 Jun 2023 16:50:34 +0930 (ACST) Date: Mon, 5 Jun 2023 16:50:34 +0930 To: binutils@sourceware.org Subject: Yet another ecoff fuzzed object fix Message-ID: MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-3033.7 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP, T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Patchwork-Original-From: Alan Modra via Binutils From: Alan Modra Reply-To: Alan Modra Errors-To: binutils-bounces+ouuuleilei=gmail.com@sourceware.org Sender: "Binutils" X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1767846358264913357?= X-GMAIL-MSGID: =?utf-8?q?1767846358264913357?= * ecoff.c (_bfd_ecoff_slurp_symbol_table): Sanity check fdr_ptr csym against remaining space for symbols. Error on out of bounds fdr_ptr fields. diff --git a/bfd/ecoff.c b/bfd/ecoff.c index c4c2e530be0..573f52d0299 100644 --- a/bfd/ecoff.c +++ b/bfd/ecoff.c @@ -956,13 +956,19 @@ _bfd_ecoff_slurp_symbol_table (bfd *abfd) char *lraw_end; HDRR *symhdr = &ecoff_data (abfd)->debug_info.symbolic_header; + if (fdr_ptr->csym == 0) + continue; if (fdr_ptr->isymBase < 0 || fdr_ptr->isymBase > symhdr->isymMax - || fdr_ptr->csym <= 0 - || fdr_ptr->csym > symhdr->isymMax - fdr_ptr->isymBase + || fdr_ptr->csym < 0 + || fdr_ptr->csym > ((long) bfd_get_symcount (abfd) + - (internal_ptr - internal)) || fdr_ptr->issBase < 0 || fdr_ptr->issBase > symhdr->issMax) - continue; + { + bfd_set_error (bfd_error_bad_value); + return false; + } lraw_src = ((char *) ecoff_data (abfd)->debug_info.external_sym + fdr_ptr->isymBase * external_sym_size); lraw_end = lraw_src + fdr_ptr->csym * external_sym_size;