From patchwork Sat Oct 29 04:53:25 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alan Modra X-Patchwork-Id: 12631 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a5d:6687:0:0:0:0:0 with SMTP id l7csp1185938wru; Fri, 28 Oct 2022 21:54:30 -0700 (PDT) X-Google-Smtp-Source: AMsMyM6GZ6eB+fhXjyi5DZQNCE+WwFPZZDFVN/cMnFPbF7tQC/WpQtoum+vyUpD8B4oYEw8qKJx1 X-Received: by 2002:a17:907:7d8b:b0:78e:2534:4fd3 with SMTP id oz11-20020a1709077d8b00b0078e25344fd3mr2480439ejc.141.1667019270805; Fri, 28 Oct 2022 21:54:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1667019270; cv=none; d=google.com; s=arc-20160816; b=DJVSvrA+MfFJ1NzXfAhTtq8xNKPCsJQhkP8sxX+8FQFCripdFIQdPL9LA+L5g1110s 72uwx2xbYrMfyAUnt4PzUDF6Ilh2FU3VlC9uhYEDk0AS/i8oQIYlbFgJFb+liBgEbif4 Pen5QfZglkuEqD5Du/gz9f1ULhKeHLtiTDy8B8XIpJuABQ73lomFAzEsmdCAIWsUACvs GkZLOxJMauXowi0sFOryE5D9Y4LPaIEW4P0N6Tp7z3DLZnDIFYwQt9VC667G8q6t2cxq f3nviuTPBx5nNe5AJyC3tslu2GAzcK5BeJJorQp01JplY+cmDRI3DkywtoWiqwW28n/U WhdQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:reply-to:from:list-subscribe:list-help:list-post :list-archive:list-unsubscribe:list-id:precedence :content-disposition:mime-version:message-id:subject:to:date :dmarc-filter:delivered-to:dkim-signature:dkim-filter; bh=1SfJlr3YAPi7w9jvWp60qVA3eXqD1HFvtP/CGyeBEXQ=; b=QKtUgl4bKzyLcjdVHERgHBtcMm4dVMpinl7X/JzmloRmb0ZPHnsIWF/CufhyvNI9gh UQ6OGuItVGz04XId2YEBDvQ5mb4GA5NtmU1WBJglnY9Ix0sXjUsTS78qLC7LMnz1mk3D 8s7aThlw9S5Kjn8XE7XuMH9ayPLb8Z0X6Fh5pLE5xeMV8bfa4ZFQw+KUKGB5ADxLV5RY Zik+9Jkj5A5gANPy6qn4N9/ua/MFKjk3uo9UsuSA+LEgax4k3PygL1hk3sojvG488dXo TMJVhqknOMOwyl17Wx60pW8XnCPWvbRmyLKlCegAOUjuCwbv/UKJrZ5aTFiPF21CgRI2 d7bw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=fKuZXkUU; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 8.43.85.97 as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from sourceware.org (server2.sourceware.org. [8.43.85.97]) by mx.google.com with ESMTPS id cs19-20020a170906dc9300b0078dcaaa2638si803483ejc.708.2022.10.28.21.54.30 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 28 Oct 2022 21:54:30 -0700 (PDT) Received-SPF: pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 8.43.85.97 as permitted sender) client-ip=8.43.85.97; Authentication-Results: mx.google.com; dkim=pass header.i=@sourceware.org header.s=default header.b=fKuZXkUU; spf=pass (google.com: domain of binutils-bounces+ouuuleilei=gmail.com@sourceware.org designates 8.43.85.97 as permitted sender) smtp.mailfrom="binutils-bounces+ouuuleilei=gmail.com@sourceware.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 61A3A385D0F1 for ; Sat, 29 Oct 2022 04:53:52 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 61A3A385D0F1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sourceware.org; s=default; t=1667019232; bh=1SfJlr3YAPi7w9jvWp60qVA3eXqD1HFvtP/CGyeBEXQ=; h=Date:To:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post: List-Help:List-Subscribe:From:Reply-To:From; b=fKuZXkUU3w+juum+cmLK1CKdILe53cPem3dy1H3QjTY2q29ybtQtkWBA+LFY6O6WZ vThbIMXfaX4DZiCss4Ont551ovfUoUcnXVC2XNQHOZW3tqcUj9wrTq8ke01JhTmwxU SuyNUMwV1XQDLUmgmk9niPn1NoCAl9eLrFGopxYw= X-Original-To: binutils@sourceware.org Delivered-To: binutils@sourceware.org Received: from mail-pl1-x635.google.com (mail-pl1-x635.google.com [IPv6:2607:f8b0:4864:20::635]) by sourceware.org (Postfix) with ESMTPS id D13E1385743A for ; Sat, 29 Oct 2022 04:53:29 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org D13E1385743A Received: by mail-pl1-x635.google.com with SMTP id p3so6510564pld.10 for ; Fri, 28 Oct 2022 21:53:29 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=1SfJlr3YAPi7w9jvWp60qVA3eXqD1HFvtP/CGyeBEXQ=; b=ovVx5J3HHSx6xVj3yrTXGB55GOyEzAsKTqJrzAy2+L+qAf6Q7m7fqKl/kE8pv0YI30 /nY/sggKH+OVZOVsNU4aRIPprbNpTv2KaPK2hiDVLeRJfyIvBJPsv0iIK33KusNG6vH+ P1r9OeLm73G6+GLGNGYDkg9QCmOXxUSUXg89ZIGQEbUURaJ67SqZcJGdsfv2rHYOVpJZ dTyGw5d40oo8V8LfrEMmkvQTsUXm74LoNx98mroHcuk+/HSYGyu9GsBHpBFkjIdWlA06 yWHJmYDs1dBvHK0q7cK+KP2tUiLRsuncwSj2xYf3xUkSJQqQMy/6u2FjS6+6X2o0WsNO zxNQ== X-Gm-Message-State: ACrzQf24xlt/1M0tVqf/+sHI5xDUtNcZBL11iLBX/F09fT152m/9xm3V 5JBvKqTV8ABIY2Eanhxm8jTa7D851k0= X-Received: by 2002:a17:90b:1d8a:b0:20f:95f9:ff34 with SMTP id pf10-20020a17090b1d8a00b0020f95f9ff34mr2915468pjb.227.1667019208384; Fri, 28 Oct 2022 21:53:28 -0700 (PDT) Received: from squeak.grove.modra.org (158.106.96.58.static.exetel.com.au. [58.96.106.158]) by smtp.gmail.com with ESMTPSA id t17-20020a170902e1d100b00186ae540083sm327036pla.91.2022.10.28.21.53.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 28 Oct 2022 21:53:27 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id 5D5FF11424AE; Sat, 29 Oct 2022 15:23:25 +1030 (ACDT) Date: Sat, 29 Oct 2022 15:23:25 +1030 To: binutils@sourceware.org Subject: pef: sanity check before malloc Message-ID: MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-3036.2 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Patchwork-Original-From: Alan Modra via Binutils From: Alan Modra Reply-To: Alan Modra Errors-To: binutils-bounces+ouuuleilei=gmail.com@sourceware.org Sender: "Binutils" X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1747996399033376559?= X-GMAIL-MSGID: =?utf-8?q?1747996399033376559?= And do the sanity check in a way that can't overflow. * pef.c (bfd_pef_parse_function_stubs): Sanity check header imported_library_count and total_imported_symbol_count before allocating memory. diff --git a/bfd/pef.c b/bfd/pef.c index d9936f750c1..334d802eb75 100644 --- a/bfd/pef.c +++ b/bfd/pef.c @@ -751,6 +751,13 @@ bfd_pef_parse_function_stubs (bfd *abfd, if (ret < 0) goto error; + if ((loaderlen - 56) / 24 < header.imported_library_count) + goto error; + + if ((loaderlen - 56 - header.imported_library_count * 24) / 4 + < header.total_imported_symbol_count) + goto error; + libraries = bfd_malloc (header.imported_library_count * sizeof (bfd_pef_imported_library)); imports = bfd_malloc @@ -758,8 +765,6 @@ bfd_pef_parse_function_stubs (bfd *abfd, if (libraries == NULL || imports == NULL) goto error; - if (loaderlen < (56 + (header.imported_library_count * 24))) - goto error; for (i = 0; i < header.imported_library_count; i++) { ret = bfd_pef_parse_imported_library @@ -768,9 +773,6 @@ bfd_pef_parse_function_stubs (bfd *abfd, goto error; } - if (loaderlen < (56 + (header.imported_library_count * 24) - + (header.total_imported_symbol_count * 4))) - goto error; for (i = 0; i < header.total_imported_symbol_count; i++) { ret = (bfd_pef_parse_imported_symbol