[PATCH][binutils][2_44] Backport Replace xmalloc with stat_alloc in ld parser (CVE-2025-1148)

Jan Beulich jbeulich@suse.com
Thu Mar 13 08:20:13 GMT 2025


On 12.03.2025 08:06, Harish.Sadineni@windriver.com wrote:
> From: Harish Sadineni <Harish.Sadineni@windriver.com>

This isn't quite right, is it? The author of a backport is usually still ...

> commit d4115c2c8d447e297ae353892de89192c1996211
> Author: Alan Modra <amodra@gmail.com>

... the original author.

> Date:   Sat Jan 11 16:19:09 2025 +1030
> 
>     Replace xmalloc with stat_alloc in ld parser
> 
>     A few place dealing with ld script handling made some attempt to free
>     memory, but this was generally ignored and would be quite a lot of
>     work to implement.  Instead, use the stat_obstack rather than
>     mallocing in many more cases.
> 
>             * ldexp.c (exp_get_fill): Use stat_alloc for fill.
>             * ldfile.c (ldfile_try_open_bfd): Don't free yylval fields.
>             * ldgram.y: Replace xmalloc with stat_alloc throughout.
>             * ldlang.c (stat_memdup, stat_strdup): New functions.
>             (ldirname): Use stat_memdup.  Don't strdup ".".
>             (output_section_callback_sort): Use stat_alloc.
>             (output_section_callback_tree_to_list): Don't free.
>             (lang_memory_region_lookup): Use stat_strdup.
>             (lang_memory_region_alias): Likewise.
>             (add_excluded_libs): Use stat_alloc and stat_memdup.
>             (ldlang_add_undef, ldlang_add_require_defined): Use stat_strdup.
>             (lang_add_nocrossref, lang_leave_overlay): Use stat_alloc.
>             (realsymbol): Use stat_strdup for return value and always
>             free symbol.
>             (lang_new_vers_pattern, lang_new_vers_node): Use stat_alloc.
>             (lang_finalize_version_expr_head): Don't free.  Delete FIXME.
>             (lang_register_vers_node): Don't free.
>             (lang_add_vers_depend): Use stat_alloc.
>             (lang_do_version_exports_section): Likewise.
>             (lang_add_unique): Use stat_alloc and stat_strdup.
>             (lang_append_dynamic_list): Use stat_alloc.
>             * ldlang.h (stat_memdup, stat_strdup): Declare.
>             * ldlex.l: Replace xstrdup with stat_strdup throughout.
>             Replace xmemdup with stat_memdup too.
>             * lexsup.c (parse_args): Don't free export list or dynamic
>             list.
> 
> (cherry pick from master: d4115c2c8d447e297ae353892de89192c1996211)
> 
> Fixes https://sourceware.org/bugzilla/show_bug.cgi?id=32576 (CVE-2025-1148)
> 
> Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>

As indicated when the more general question was raised, I think what's missing
here is a (good) justification for putting this on a stable branch. It's a
relatively large change for a relatively low priority bug. Unless of course
you know facts beyond what is stated there. Without extra justification
personally I'd reject this; I'm happy for Nick or Alan to override me, though.

Jan


More information about the Binutils mailing list