[binutils-gdb] asan: buffer overflow in elf32_dlx_relocate26
Alan Modra
amodra@sourceware.org
Sun Jun 28 02:53:15 GMT 2026
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=114e3aae2b7e34057c8909301eaf78c15687e8e5
commit 114e3aae2b7e34057c8909301eaf78c15687e8e5
Author: Alan Modra <amodra@gmail.com>
Date: Sun Jun 28 09:11:46 2026 +0930
asan: buffer overflow in elf32_dlx_relocate26
* elf32-dlx.c (elf32_dlx_relocate26): Sanity check reloc offset.
(elf32_dlx_relocate16): Likewise.
(_bfd_dlx_elf_hi16_reloc): Likewise, and remove ineffective
existing check.
Diff:
---
bfd/elf32-dlx.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/bfd/elf32-dlx.c b/bfd/elf32-dlx.c
index 2dfeb4d7390..0f9a49695d7 100644
--- a/bfd/elf32-dlx.c
+++ b/bfd/elf32-dlx.c
@@ -77,6 +77,10 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd,
return bfd_reloc_ok;
}
+ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
+ input_section, reloc_entry->address))
+ return bfd_reloc_outofrange;
+
ret = bfd_reloc_ok;
if (bfd_is_und_section (symbol->section)
@@ -89,9 +93,6 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd,
relocation += reloc_entry->addend;
relocation += bfd_get_16 (abfd, (bfd_byte *)data + reloc_entry->address);
- if (reloc_entry->address > bfd_get_section_limit (abfd, input_section))
- return bfd_reloc_outofrange;
-
bfd_put_16 (abfd, (short)((relocation >> 16) & 0xFFFF),
(bfd_byte *)data + reloc_entry->address);
@@ -143,6 +144,10 @@ elf32_dlx_relocate16 (bfd *abfd,
return bfd_reloc_undefined;
}
+ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
+ input_section, reloc_entry->address))
+ return bfd_reloc_outofrange;
+
insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address);
allignment = 1 << (input_section->output_section->alignment_power - 1);
vallo = insn & 0x0000FFFF;
@@ -206,6 +211,10 @@ elf32_dlx_relocate26 (bfd *abfd,
return bfd_reloc_undefined;
}
+ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
+ input_section, reloc_entry->address))
+ return bfd_reloc_outofrange;
+
insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address);
allignment = 1 << (input_section->output_section->alignment_power - 1);
vallo = insn & 0x03FFFFFF;
More information about the Binutils-cvs
mailing list