[PATCH][binutils][2_44] Backport Replace xmalloc with stat_alloc in ld parser (CVE-2025-1148)

Jan Beulich jbeulich@suse.com
Thu Mar 13 10:40:08 GMT 2025


On 13.03.2025 10:39, Sadineni, Harish wrote:
>>> This isn't quite right, is it? The author of a backport is usually still ...
>>> ... the original author.
> 
> Alright, I will add the "Signed-off-by: Modra amodra@gmail.com" before mine.

I don't think you may take an S-o-b out of thin air. It's From: that you want
to adjust.

>>> As indicated when the more general question was raised, I think what's missing
>>> here is a (good) justification for putting this on a stable branch. It's a
>>> relatively large change for a relatively low priority bug. Unless of course
>>> you know facts beyond what is stated there. Without extra justification
>>> personally I'd reject this; I'm happy for Nick or Alan to override me, though.
> 
> Since we are backporting, I have used the same commit message. Could you kindly clarify what type of justification should be added?.

See my earlier reply on the matter: A post-commit-message remark may be what's
best to use in such a case. However, ...

> There are four CVEs associated with this bug (32576):
> https://nvd.nist.gov/vuln/detail/CVE-2025-1148
> https://nvd.nist.gov/vuln/detail/CVE-2025-1150
> https://nvd.nist.gov/vuln/detail/CVE-2025-1151
> https://nvd.nist.gov/vuln/detail/CVE-2025-1152

... there being whatever number of CVEs isn't a sufficient justification, imo.
CVEs, sadly, vary greatly in how important (and sometimes even relevant) it is
that they cover.

Jan


More information about the Binutils mailing list