RFC: Fix for CVE-2026-19548

Maciej W. Rozycki macro@orcam.me.uk
Fri Aug 14 02:32:04 GMT 2026


On Fri, 14 Aug 2026, Alan Modra wrote:

> Hmm..  This is likely a bug in e34fd4bfa6d7.  I see a bfd_release in
> _bfd_compute_and_push_armap that will lose the memory for
> ardata->symdefs set up in _bfd_load_armap.

 Good catch!  Since `_bfd_compute_and_push_armap' uses `bfd_alloc' for 
temporary storage only, I think the best way to get this sorted will be 
just using a local objalloc structure rather than attaching it to the 
archive BFD.  It seems really straightforward and will avoid making the 
dummy allocation at the top, so I guess the original author of this code 
just didn't bother, because it didn't matter for pre-e34fd4bfa6d7 use.

 I have a fix in verification now; will post tomorrow as it's quite late 
here already.

 Thank you for narrowing this down, and the heads-up!

  Maciej


More information about the Binutils mailing list