Recursion in as_info_where

Jan Beulich jbeulich@suse.com
Wed Feb 1 09:24:25 GMT 2023


On 01.02.2023 07:36, Alan Modra via Binutils wrote:
> This function has a gas_assert, ie. possible call to as_abort, which
> calls as_report_context, which calls as_info_where.  Attached fuzzer
> testcase managed to trigger a stack overflow.
> 
> 	* messages.c (as_info_where): Don't gas_assert.
> 
> diff --git a/gas/messages.c b/gas/messages.c
> index 0db075d779c..7c018acf69f 100644
> --- a/gas/messages.c
> +++ b/gas/messages.c
> @@ -141,8 +141,6 @@ as_info_where (const char *file, unsigned int line, unsigned int indent,
>    va_list args;
>    char buffer[2000];
>  
> -  gas_assert (file != NULL && line > 0 && indent <= INT_MAX);

If this go in the way, isn't it that the assertion actually triggered?
In which case shouldn't the cause for it triggering be addressed
instead, to avoid subsequent knock-on damage (e.g. from de-referencing
"file"? (I may want to play with the testcase a little myself.)

Jan


More information about the Binutils mailing list