[PATCH][binutils][2_44] Backport Replace xmalloc with stat_alloc in ld parser (CVE-2025-1148)
Jan Beulich
jbeulich@suse.com
Thu Mar 13 08:20:13 GMT 2025
On 12.03.2025 08:06, Harish.Sadineni@windriver.com wrote:
> From: Harish Sadineni <Harish.Sadineni@windriver.com>
This isn't quite right, is it? The author of a backport is usually still ...
> commit d4115c2c8d447e297ae353892de89192c1996211
> Author: Alan Modra <amodra@gmail.com>
... the original author.
> Date: Sat Jan 11 16:19:09 2025 +1030
>
> Replace xmalloc with stat_alloc in ld parser
>
> A few place dealing with ld script handling made some attempt to free
> memory, but this was generally ignored and would be quite a lot of
> work to implement. Instead, use the stat_obstack rather than
> mallocing in many more cases.
>
> * ldexp.c (exp_get_fill): Use stat_alloc for fill.
> * ldfile.c (ldfile_try_open_bfd): Don't free yylval fields.
> * ldgram.y: Replace xmalloc with stat_alloc throughout.
> * ldlang.c (stat_memdup, stat_strdup): New functions.
> (ldirname): Use stat_memdup. Don't strdup ".".
> (output_section_callback_sort): Use stat_alloc.
> (output_section_callback_tree_to_list): Don't free.
> (lang_memory_region_lookup): Use stat_strdup.
> (lang_memory_region_alias): Likewise.
> (add_excluded_libs): Use stat_alloc and stat_memdup.
> (ldlang_add_undef, ldlang_add_require_defined): Use stat_strdup.
> (lang_add_nocrossref, lang_leave_overlay): Use stat_alloc.
> (realsymbol): Use stat_strdup for return value and always
> free symbol.
> (lang_new_vers_pattern, lang_new_vers_node): Use stat_alloc.
> (lang_finalize_version_expr_head): Don't free. Delete FIXME.
> (lang_register_vers_node): Don't free.
> (lang_add_vers_depend): Use stat_alloc.
> (lang_do_version_exports_section): Likewise.
> (lang_add_unique): Use stat_alloc and stat_strdup.
> (lang_append_dynamic_list): Use stat_alloc.
> * ldlang.h (stat_memdup, stat_strdup): Declare.
> * ldlex.l: Replace xstrdup with stat_strdup throughout.
> Replace xmemdup with stat_memdup too.
> * lexsup.c (parse_args): Don't free export list or dynamic
> list.
>
> (cherry pick from master: d4115c2c8d447e297ae353892de89192c1996211)
>
> Fixes https://sourceware.org/bugzilla/show_bug.cgi?id=32576 (CVE-2025-1148)
>
> Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
As indicated when the more general question was raised, I think what's missing
here is a (good) justification for putting this on a stable branch. It's a
relatively large change for a relatively low priority bug. Unless of course
you know facts beyond what is stated there. Without extra justification
personally I'd reject this; I'm happy for Nick or Alan to override me, though.
Jan
More information about the Binutils
mailing list