[PATCH][binutils][2_40 1/4] Backport fix for PR 32642(CVE-2025-1180)

Jan Beulich jbeulich@suse.com
Mon Jun 2 06:26:44 GMT 2025


On 31.05.2025 02:34, Alan Modra wrote:
> On Thu, May 29, 2025 at 01:29:23AM -0700, Harish.Sadineni@windriver.com wrote:
>> Backporting the fix from PR 32636 to fix PR 32642 (ld SEGV (illegal read access)
>> in _bfd_elf_write_section_eh_frame (bfd/elf-eh-frame.c:2234:29) with
>>  --gc-sections --gc-keep-exported option)
>>
>> https://nvd.nist.gov/vuln/detail/CVE-2025-1180 is associated with
>> PR32642 which will get fixed with commit from PR 32636.
>>
>> (cherry picked from commit: f9978defb6fab0bd8583942d97c112b0932ac814)
> 
> Please don't post patches that are just cherry-picks.  If you think
> you need a backport to a branch, just ask.
> 
> In this case as with the others posted in this email thread, I would
> deny the request.  We generally don't backport fuzzed object file
> fixes as a matter of princple unless the fix is very small and obvious
> and/or the object file could possibly occur without fuzzing.

+1, fwiw.

Jan

> The fact that there is a CVE doesn't impress.  To put it bluntly, it
> seems to me that many CVEs are raised as an ego stroking exercise by
> people running fuzzers.
> 
> I'll also note that I found your emails in my gmail spam folder.  Very
> likely that is due to other gmail subscribers to the binutils mailing
> list deciding that you are just spamming the list.  To those that may
> have done this:  Please don't tell google that patches posted to
> binutils@sourceware.org are spam.  Run a local email filter instead if
> you must.
> 



More information about the Binutils mailing list