If reloc_size is zero, we could reach this point with a null pointer, and dereference it. -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: reloc2.txt URL: <https://sourceware.org/pipermail/binutils/attachments/20070725/9a3b005b/attachment.txt>