[PATCH][binutils][2_40 1/4] Backport fix for PR 32642(CVE-2025-1180)

Alan Modra amodra@gmail.com
Sat May 31 00:34:23 GMT 2025


On Thu, May 29, 2025 at 01:29:23AM -0700, Harish.Sadineni@windriver.com wrote:
> Backporting the fix from PR 32636 to fix PR 32642 (ld SEGV (illegal read access)
> in _bfd_elf_write_section_eh_frame (bfd/elf-eh-frame.c:2234:29) with
>  --gc-sections --gc-keep-exported option)
> 
> https://nvd.nist.gov/vuln/detail/CVE-2025-1180 is associated with
> PR32642 which will get fixed with commit from PR 32636.
> 
> (cherry picked from commit: f9978defb6fab0bd8583942d97c112b0932ac814)

Please don't post patches that are just cherry-picks.  If you think
you need a backport to a branch, just ask.

In this case as with the others posted in this email thread, I would
deny the request.  We generally don't backport fuzzed object file
fixes as a matter of princple unless the fix is very small and obvious
and/or the object file could possibly occur without fuzzing.

The fact that there is a CVE doesn't impress.  To put it bluntly, it
seems to me that many CVEs are raised as an ego stroking exercise by
people running fuzzers.

I'll also note that I found your emails in my gmail spam folder.  Very
likely that is due to other gmail subscribers to the binutils mailing
list deciding that you are just spamming the list.  To those that may
have done this:  Please don't tell google that patches posted to
binutils@sourceware.org are spam.  Run a local email filter instead if
you must.

-- 
Alan Modra


More information about the Binutils mailing list