PR 34327 Out of bounds accesses in reloc special functions.

Hans-Peter Nilsson hp@bitrange.com
Thu Jul 2 03:40:40 GMT 2026


On Thu, 2 Jul 2026, Alan Modra wrote:

> As per the PR, s12z lacked any reloc offset sanity checking, the
> others all just checked that the offset started within the section
> rather than checking the field was contained in the section.
> 
> Using the proper check for mmix exposed a problem in the howto table,
> present since the initial mmix commit.

Looks like it; R_MMIX_BASE_PLUS_OFFSET was there originally, but 
most of the implementation came later.

>  The R_MMIX_BASE_PLUS_OFFSET
> field is actually two bytes, located at the reloc address.  Making it
> an eight byte field is just wrong, as doing that indicates the field
> is at the reloc address plus six bytes for a big-endian target.

Yeah, I might have misunderstood a thing here.

> Presumably this was done for overlow reporting, which is properly done
> by appropriately setting complain_on_overflow.

Which you now change to complain_overflow_dont?

Not saying the change is incorrect (it certainly looks right, 
thanks), because if it was, I have confidence that the 
test-suite would trigger a failure, but that wording is 
confusing.

brgds, H-P


More information about the Binutils mailing list