RFC: Fix for CVE-2026-19548

Maciej W. Rozycki macro@orcam.me.uk
Fri Aug 14 16:25:52 GMT 2026


On Fri, 14 Aug 2026, Maciej W. Rozycki wrote:

> > Hmm..  This is likely a bug in e34fd4bfa6d7.  I see a bfd_release in
> > _bfd_compute_and_push_armap that will lose the memory for
> > ardata->symdefs set up in _bfd_load_armap.
> 
>  Good catch!  Since `_bfd_compute_and_push_armap' uses `bfd_alloc' for 
> temporary storage only, I think the best way to get this sorted will be 
> just using a local objalloc structure rather than attaching it to the 
> archive BFD.  It seems really straightforward and will avoid making the 
> dummy allocation at the top, so I guess the original author of this code 
> just didn't bother, because it didn't matter for pre-e34fd4bfa6d7 use.
> 
>  I have a fix in verification now; will post tomorrow as it's quite late 
> here already.

 Fix now posted, at 
<https://inbox.sourceware.org/binutils/alpine.DEB.2.21.2608141637320.14132@angie.orcam.me.uk/>.

  Maciej


More information about the Binutils mailing list