[binutils-gdb] Fix a division by zero error when processing secondary relocs in a fuzzed input file.

Nick Clifton nickc@sourceware.org
Thu Sep 3 15:12:15 GMT 2020


https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ac267c754cecd2bbbfc71feb9ca8ec84f6754cb4

commit ac267c754cecd2bbbfc71feb9ca8ec84f6754cb4
Author: Nick Clifton <nickc@redhat.com>
Date:   Thu Sep 3 16:11:43 2020 +0100

    Fix a division by zero error when processing secondary relocs in a fuzzed input file.
    
            PR 26521
            * elf.c (_bfd_elf_write_secondary_reloc_section): Check for
            secondary reloc sections with a zero sh_entsize field.

Diff:
---
 bfd/ChangeLog |  6 ++++++
 bfd/elf.c     | 11 +++++++++++
 2 files changed, 17 insertions(+)

diff --git a/bfd/ChangeLog b/bfd/ChangeLog
index 2dc5b542fb1..1b58f9517ce 100644
--- a/bfd/ChangeLog
+++ b/bfd/ChangeLog
@@ -1,3 +1,9 @@
+2020-09-03  Nick Clifton  <nickc@redhat.com>
+
+	PR 26521
+	* elf.c (_bfd_elf_write_secondary_reloc_section): Check for
+	secondary reloc sections with a zero sh_entsize field.
+
 2020-09-03  Nelson Chu  <nelson.chu@sifive.com>
 
 	* elfnn-riscv.c (riscv_i_or_e_p): Minor cleanup for warnings/errors.
diff --git a/bfd/elf.c b/bfd/elf.c
index f32118ad404..ac2095f787d 100644
--- a/bfd/elf.c
+++ b/bfd/elf.c
@@ -12847,6 +12847,17 @@ _bfd_elf_write_secondary_reloc_section (bfd *abfd, asection *sec)
 	      continue;
 	    }
 
+	  if (hdr->sh_entsize == 0)
+	    {
+	      _bfd_error_handler
+		/* xgettext:c-format */
+		(_("%pB(%pA): error: secondary reloc section has zero sized entries"),
+		 abfd, relsec);
+	      bfd_set_error (bfd_error_bad_value);
+	      result = FALSE;
+	      continue;
+	    }
+
 	  reloc_count = hdr->sh_size / hdr->sh_entsize;
 	  if (reloc_count <= 0)
 	    {


More information about the Binutils-cvs mailing list