[binutils-gdb] asan: buffer overflow in sh_reloc

Alan Modra amodra@sourceware.org
Wed Dec 14 11:44:18 GMT 2022


https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ad2f3a3f72a57fcce5213567fd77d920e953316a

commit ad2f3a3f72a57fcce5213567fd77d920e953316a
Author: Alan Modra <amodra@gmail.com>
Date:   Wed Dec 14 14:46:07 2022 +1030

    asan: buffer overflow in sh_reloc
    
            * coff-sh.c (sh_reloc): Use bfd_reloc_offset_in_range.

Diff:
---
 bfd/coff-sh.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/bfd/coff-sh.c b/bfd/coff-sh.c
index c5b69a8592f..d030c475539 100644
--- a/bfd/coff-sh.c
+++ b/bfd/coff-sh.c
@@ -597,7 +597,8 @@ sh_reloc (bfd *      abfd,
       && bfd_is_und_section (symbol_in->section))
     return bfd_reloc_undefined;
 
-  if (addr > input_section->size)
+  if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, input_section,
+				  addr))
     return bfd_reloc_outofrange;
 
   sym_value = get_symbol_value (symbol_in);


More information about the Binutils-cvs mailing list