diff options
author | Britney Fransen <brfransen@gmail.com> | 2018-06-04 20:02:16 (GMT) |
---|---|---|
committer | Britney Fransen <brfransen@gmail.com> | 2018-06-04 20:02:16 (GMT) |
commit | d2a9ea85e4263927ead4d0aaf7c22a409c8eb80d (patch) | |
tree | 644923011dc9e6c4fb98228092a6e00a89a30b15 /abs/core/binutils/0001-PR22741-objcopy-segfault-on-fuzzed-COFF-object.patch | |
parent | c246c878f23bbd980ff15b379ae516d4b72b7668 (diff) | |
download | linhes_pkgbuild-d2a9ea85e4263927ead4d0aaf7c22a409c8eb80d.zip linhes_pkgbuild-d2a9ea85e4263927ead4d0aaf7c22a409c8eb80d.tar.gz linhes_pkgbuild-d2a9ea85e4263927ead4d0aaf7c22a409c8eb80d.tar.bz2 |
binutils: update to 2.30
Diffstat (limited to 'abs/core/binutils/0001-PR22741-objcopy-segfault-on-fuzzed-COFF-object.patch')
-rw-r--r-- | abs/core/binutils/0001-PR22741-objcopy-segfault-on-fuzzed-COFF-object.patch | 29 |
1 files changed, 29 insertions, 0 deletions
diff --git a/abs/core/binutils/0001-PR22741-objcopy-segfault-on-fuzzed-COFF-object.patch b/abs/core/binutils/0001-PR22741-objcopy-segfault-on-fuzzed-COFF-object.patch new file mode 100644 index 0000000..24c814e --- /dev/null +++ b/abs/core/binutils/0001-PR22741-objcopy-segfault-on-fuzzed-COFF-object.patch @@ -0,0 +1,29 @@ +From eb77f6a4621795367a39cdd30957903af9dbb815 Mon Sep 17 00:00:00 2001 +From: Alan Modra <amodra@gmail.com> +Date: Sat, 27 Jan 2018 08:19:33 +1030 +Subject: [PATCH] PR22741, objcopy segfault on fuzzed COFF object + + PR 22741 + * coffgen.c (coff_pointerize_aux): Ensure auxent tagndx is in + range before converting to a symbol table pointer. +--- + bfd/coffgen.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/bfd/coffgen.c b/bfd/coffgen.c +index b2410873d0..4f90eaddd9 100644 +--- a/bfd/coffgen.c ++++ b/bfd/coffgen.c +@@ -1555,7 +1555,8 @@ coff_pointerize_aux (bfd *abfd, + } + /* A negative tagndx is meaningless, but the SCO 3.2v4 cc can + generate one, so we must be careful to ignore it. */ +- if (auxent->u.auxent.x_sym.x_tagndx.l > 0) ++ if ((unsigned long) auxent->u.auxent.x_sym.x_tagndx.l ++ < obj_raw_syment_count (abfd)) + { + auxent->u.auxent.x_sym.x_tagndx.p = + table_base + auxent->u.auxent.x_sym.x_tagndx.l; +-- +2.16.2 + |