[binutils-gdb] buffer overflow in process_sht_group_entries

Alan Modra amodra@sourceware.org
Sun Aug 17 06:33:08 GMT 2025


https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f586f9b61d1e5d91f010e68922b8c8b86f787a27

commit f586f9b61d1e5d91f010e68922b8c8b86f787a27
Author: Alan Modra <amodra@gmail.com>
Date:   Sun Aug 17 15:13:06 2025 +0930

    buffer overflow in process_sht_group_entries
    
    An oss-fuzz testcase with a SHT_GROUP section named .debug managed to
    break objcopy --compress-debug-sections.  The underlying problem is
    that SEC_DEBUGGING is set by section name tests, thus the SHT_GROUP
    section gets compressed.  The compressed section data is smaller than
    the original section sh_size, and process_sht_group_entries tries to
    look at sh_size worth of entries.  The patch fixes this mess by simply
    not setting SEC_DEBUGGING on SHT_GROUP sections.
    
    Note that it isn't correct to restrict SEC_DEBUGGING to SHT_PROGBITS
    sections, as that will break processor/os special sections for debug.
    eg. SHT_MIPS_DEBUG.
    
            * elf.c (_bfd_elf_make_section_from_shdr): Don't set
            SEC_DEBUGGING on SEC_GROUP sections no matter their name.

Diff:
---
 bfd/elf.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/bfd/elf.c b/bfd/elf.c
index 4051f2f9329..84a220f01cc 100644
--- a/bfd/elf.c
+++ b/bfd/elf.c
@@ -957,7 +957,7 @@ _bfd_elf_make_section_from_shdr (bfd *abfd,
       break;
     }
 
-  if ((flags & SEC_ALLOC) == 0)
+  if ((flags & (SEC_ALLOC | SEC_GROUP)) == 0)
     {
       /* The debugging sections appear to be recognized only by name,
 	 not any sort of flag.  Their SEC_ALLOC bits are cleared.  */


More information about the Binutils-cvs mailing list