[binutils-gdb] NULL dereference read in som_write_object_contents

Alan Modra amodra@sourceware.org
Sat Oct 29 04:54:17 GMT 2022


https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=13de66dd346c4a4eddf62c3b97747d707c5ed78e

commit 13de66dd346c4a4eddf62c3b97747d707c5ed78e
Author: Alan Modra <amodra@gmail.com>
Date:   Sat Oct 29 10:31:01 2022 +1030

    NULL dereference read in som_write_object_contents
    
    objcopy copy_object may omit the call to bfd_copy_private_bfd_data for
    various conditions deemed non-fatal, in which case obj_som_exec_data
    will be NULL for the output file.
    
            * som.c (som_finish_writing): Don't dereference NULL
            obj_som_exec_data.

Diff:
---
 bfd/som.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/bfd/som.c b/bfd/som.c
index b3a72e36ede..7a5ee35f0e2 100644
--- a/bfd/som.c
+++ b/bfd/som.c
@@ -4211,7 +4211,7 @@ som_finish_writing (bfd *abfd)
 
   /* Setting of the system_id has to happen very late now that copying of
      BFD private data happens *after* section contents are set.  */
-  if (abfd->flags & (EXEC_P | DYNAMIC))
+  if ((abfd->flags & (EXEC_P | DYNAMIC)) && obj_som_exec_data (abfd))
     obj_som_file_hdr (abfd)->system_id = obj_som_exec_data (abfd)->system_id;
   else if (bfd_get_mach (abfd) == pa20)
     obj_som_file_hdr (abfd)->system_id = CPU_PA_RISC2_0;
@@ -4242,7 +4242,8 @@ som_finish_writing (bfd *abfd)
 
       exec_header = obj_som_exec_hdr (abfd);
       exec_header->exec_entry = bfd_get_start_address (abfd);
-      exec_header->exec_flags = obj_som_exec_data (abfd)->exec_flags;
+      if (obj_som_exec_data (abfd))
+	exec_header->exec_flags = obj_som_exec_data (abfd)->exec_flags;
 
       /* Oh joys.  Ram some of the BSS data into the DATA section
 	 to be compatible with how the hp linker makes objects


More information about the Binutils-cvs mailing list