[PATCH v2][binutils][2_44] Backport Replace xmalloc with stat_alloc in ld parser
Jan Beulich
jbeulich@suse.com
Fri Mar 14 11:06:04 GMT 2025
On 13.03.2025 12:33, Harish.Sadineni@windriver.com wrote:
> From: Alan Modra <amodra@gmail.com>
>
> A few place dealing with ld script handling made some attempt to free
> memory, but this was generally ignored and would be quite a lot of
> work to implement. Instead, use the stat_obstack rather than
> mallocing in many more cases.
>
> * ldexp.c (exp_get_fill): Use stat_alloc for fill.
> * ldfile.c (ldfile_try_open_bfd): Don't free yylval fields.
> * ldgram.y: Replace xmalloc with stat_alloc throughout.
> * ldlang.c (stat_memdup, stat_strdup): New functions.
> (ldirname): Use stat_memdup. Don't strdup ".".
> (output_section_callback_sort): Use stat_alloc.
> (output_section_callback_tree_to_list): Don't free.
> (lang_memory_region_lookup): Use stat_strdup.
> (lang_memory_region_alias): Likewise.
> (add_excluded_libs): Use stat_alloc and stat_memdup.
> (ldlang_add_undef, ldlang_add_require_defined): Use stat_strdup.
> (lang_add_nocrossref, lang_leave_overlay): Use stat_alloc.
> (realsymbol): Use stat_strdup for return value and always
> free symbol.
> (lang_new_vers_pattern, lang_new_vers_node): Use stat_alloc.
> (lang_finalize_version_expr_head): Don't free. Delete FIXME.
> (lang_register_vers_node): Don't free.
> (lang_add_vers_depend): Use stat_alloc.
> (lang_do_version_exports_section): Likewise.
> (lang_add_unique): Use stat_alloc and stat_strdup.
> (lang_append_dynamic_list): Use stat_alloc.
> * ldlang.h (stat_memdup, stat_strdup): Declare.
> * ldlex.l: Replace xstrdup with stat_strdup throughout.
> Replace xmemdup with stat_memdup too.
> * lexsup.c (parse_args): Don't free export list or dynamic
> list.
>
> (Backporting from master: d4115c2c8d447e297ae353892de89192c1996211)
>
> Fixes https://sourceware.org/bugzilla/show_bug.cgi?id=32576
>
> There are four CVEs associated with this bug (32576):
> https://nvd.nist.gov/vuln/detail/CVE-2025-1148
> https://nvd.nist.gov/vuln/detail/CVE-2025-1150
> https://nvd.nist.gov/vuln/detail/CVE-2025-1151
> https://nvd.nist.gov/vuln/detail/CVE-2025-1152
>
> Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
Mind me asking what the purpose of this re-submission is? You were told
already that this kind of work is not wanted to be put on branches.
Unless of course you can point out an issue it fixes beyond the CVEs
that you list, all of which aren't really an issue afaict.
Jan
More information about the Binutils
mailing list