PR26539, memory leak in inflate.c
Hans-Peter Nilsson
hp@bitrange.com
Fri Jan 15 21:06:39 GMT 2021
On Fri, 15 Jan 2021, Alan Modra via Binutils wrote:
> Like the PR15356 fix for the same leak in bfd, but for readelf.c
>
> PR 26539
> * readelf.c (uncompress_section_contents): Always call inflateEnd.
>
> diff --git a/binutils/readelf.c b/binutils/readelf.c
> index ad16b4571c..d828d5636d 100644
> --- a/binutils/readelf.c
> +++ b/binutils/readelf.c
> @@ -14221,15 +14221,15 @@ uncompress_section_contents (unsigned char ** buffer,
> while (strm.avail_in > 0)
> {
> if (rc != Z_OK)
> - goto fail;
> + break;
> strm.next_out = ((Bytef *) uncompressed_buffer
> + (uncompressed_size - strm.avail_out));
> rc = inflate (&strm, Z_FINISH);
> if (rc != Z_STREAM_END)
> - goto fail;
> + break;
> rc = inflateReset (& strm);
> }
> - rc = inflateEnd (& strm);
> + rc |= inflateEnd (& strm);
> if (rc != Z_OK
> || strm.avail_out != 0)
> goto fail;
I don't know zlib, but I'm guessing (i.e. it's the only
definition that makes sense there) there's a "#define Z_OK 0" or
equivalent somewhere? If not, "if (rc == Z_OK) rc = inflateEnd
(& strm);" would fix a bug last there.
brgds, H-P
More information about the Binutils
mailing list