[binutils-gdb] objcopy of mach-o indirect symbols

Alan Modra amodra@sourceware.org
Fri Feb 10 00:57:47 GMT 2023


https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7027a373b2422eb682df69639308134283edd0b8

commit 7027a373b2422eb682df69639308134283edd0b8
Author: Alan Modra <amodra@gmail.com>
Date:   Fri Feb 10 10:54:32 2023 +1030

    objcopy of mach-o indirect symbols
    
    Anti-fuzzer measure.  I'm not sure what the correct fix is for
    objcopy.  Probably the BFD_MACH_O_S_NON_LAZY_SYMBOL_POINTERS,
    BFD_MACH_O_S_LAZY_SYMBOL_POINTERS and BFD_MACH_O_S_SYMBOL_STUBS
    contents should be read.
    
            * mach-o.c (bfd_mach_o_section_get_nbr_indirect): Omit sections
            with NULL sec->indirect_syms.

Diff:
---
 bfd/mach-o.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/bfd/mach-o.c b/bfd/mach-o.c
index 15da219ba57..a910e1146ea 100644
--- a/bfd/mach-o.c
+++ b/bfd/mach-o.c
@@ -526,6 +526,15 @@ bfd_mach_o_section_get_nbr_indirect (bfd *abfd, bfd_mach_o_section *sec)
 {
   unsigned int elsz;
 
+  /* FIXME: This array is set by the assembler but does not seem to be
+     set anywhere for objcopy.  Since bfd_mach_o_build_dysymtab will
+     not fill in output bfd_mach_o_dysymtab_command indirect_syms when
+     this array is NULL we may as well return zero for the size.
+     This is enough to stop objcopy allocating huge amounts of memory
+     for indirect symbols in fuzzed object files.  */
+  if (sec->indirect_syms == NULL)
+    return 0;
+
   elsz = bfd_mach_o_section_get_entry_size (abfd, sec);
   if (elsz == 0)
     return 0;


More information about the Binutils-cvs mailing list