eh-frame: CIE initial_instructions overflow

nick clifton nickc@redhat.com
Thu Dec 19 11:34:00 GMT 2013


Hi Christophe,

> Currently, in bfd/elf-eh-frame.c we have a definition of struct cie
> which ends with:
>    unsigned char initial_instructions[50];

This is a bug...

> In _bfd_elf_parse_eh_frame(), we have:
>        initial_insn_length = end - buf;
>        if (initial_insn_length <= sizeof (cie->initial_instructions))
>          {
>            cie->initial_insn_length = initial_insn_length;
>            memcpy (cie->initial_instructions, buf, initial_insn_length);
>          }

IMHO - there should be no fixed size for the initial_instructions 
buffer.  Instead the code at this point should allocate and copy the 
buffer that has just been created.

Cheers
   Nick



More information about the Binutils mailing list