USE_MMAP fuzzed object file attacks

Alan Modra amodra@gmail.com
Thu Apr 4 02:51:17 GMT 2024


I committed a broken patch.

	* aoutx.h (aout_get_external_symbols): Remove wrong #else and
	unneeded casts.
	* pdp11.c (aout_get_external_symbols): Likewise.

diff --git a/bfd/aoutx.h b/bfd/aoutx.h
index fb6326d79d1..d98ba61a339 100644
--- a/bfd/aoutx.h
+++ b/bfd/aoutx.h
@@ -1322,21 +1322,20 @@ aout_get_external_symbols (bfd *abfd)
 	  if (! bfd_get_file_window (abfd, obj_sym_filepos (abfd), amt,
 				     &obj_aout_sym_window (abfd), true))
 	    return false;
-	  syms = (struct external_nlist *) obj_aout_sym_window (abfd).data;
+	  syms = obj_aout_sym_window (abfd).data;
 	}
       else
-#else
+#endif
 	{
 	  /* We allocate using malloc to make the values easy to free
 	     later on.  If we put them on the objalloc it might not be
 	     possible to free them.  */
 	  if (bfd_seek (abfd, obj_sym_filepos (abfd), SEEK_SET) != 0)
 	    return false;
-	  syms = (struct external_nlist *) _bfd_malloc_and_read (abfd, amt, amt);
+	  syms = _bfd_malloc_and_read (abfd, amt, amt);
 	  if (syms == NULL)
 	    return false;
 	}
-#endif
 
       obj_aout_external_syms (abfd) = syms;
       obj_aout_external_sym_count (abfd) = count;
diff --git a/bfd/pdp11.c b/bfd/pdp11.c
index f9ded64c933..b20c39659db 100644
--- a/bfd/pdp11.c
+++ b/bfd/pdp11.c
@@ -1299,21 +1299,20 @@ aout_get_external_symbols (bfd *abfd)
 	  if (! bfd_get_file_window (abfd, obj_sym_filepos (abfd), amt,
 				     &obj_aout_sym_window (abfd), true))
 	    return false;
-	  syms = (struct external_nlist *) obj_aout_sym_window (abfd).data;
+	  syms = obj_aout_sym_window (abfd).data;
 	}
       else
-#else
+#endif
 	{
 	  /* We allocate using malloc to make the values easy to free
 	     later on.  If we put them on the objalloc it might not be
 	     possible to free them.  */
 	  if (bfd_seek (abfd, obj_sym_filepos (abfd), SEEK_SET) != 0)
 	    return false;
-	  syms = (struct external_nlist *) _bfd_malloc_and_read (abfd, amt, amt);
+	  syms = _bfd_malloc_and_read (abfd, amt, amt);
 	  if (syms == NULL)
 	    return false;
 	}
-#endif
 
       obj_aout_external_syms (abfd) = syms;
       obj_aout_external_sym_count (abfd) = count;

-- 
Alan Modra
Australia Development Lab, IBM


More information about the Binutils mailing list