RFC: Fix for CVE-2026-19548
Maciej W. Rozycki
macro@orcam.me.uk
Fri Aug 14 16:25:52 GMT 2026
On Fri, 14 Aug 2026, Maciej W. Rozycki wrote:
> > Hmm.. This is likely a bug in e34fd4bfa6d7. I see a bfd_release in
> > _bfd_compute_and_push_armap that will lose the memory for
> > ardata->symdefs set up in _bfd_load_armap.
>
> Good catch! Since `_bfd_compute_and_push_armap' uses `bfd_alloc' for
> temporary storage only, I think the best way to get this sorted will be
> just using a local objalloc structure rather than attaching it to the
> archive BFD. It seems really straightforward and will avoid making the
> dummy allocation at the top, so I guess the original author of this code
> just didn't bother, because it didn't matter for pre-e34fd4bfa6d7 use.
>
> I have a fix in verification now; will post tomorrow as it's quite late
> here already.
Fix now posted, at
<https://inbox.sourceware.org/binutils/alpine.DEB.2.21.2608141637320.14132@angie.orcam.me.uk/>.
Maciej
More information about the Binutils
mailing list