From b715d2c84ba30c1d0a3f4fa18fd5e4929f82fa34 Mon Sep 17 00:00:00 2001 From: "H.J. Lu" Date: Sat, 21 Jun 2025 06:52:00 +0800 Subject: [PATCH] elf: Report corrupted group section Report corrupted group section instead of trying to recover. PR binutils/33050 * elf.c (bfd_elf_set_group_contents): Report corrupted group section. Signed-off-by: H.J. Lu --- bfd/elf.c | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/bfd/elf.c b/bfd/elf.c index 14ce15c7254..015b2497b2f 100644 --- a/bfd/elf.c +++ b/bfd/elf.c @@ -3833,6 +3833,7 @@ bfd_elf_set_group_contents (bfd *abfd, asection *sec, void *failedptrarg) asection *elt, *first; unsigned char *loc; bool gas; + bool corrupted; /* Ignore linker created group section. See elfNN_ia64_object_p in elfxx-ia64.c. */ @@ -3974,17 +3975,23 @@ bfd_elf_set_group_contents (bfd *abfd, asection *sec, void *failedptrarg) /* We should always get here with loc == sec->contents + 4, but it is possible to craft bogus SHT_GROUP sections that will cause segfaults in objcopy without checking loc here and in the loop above. */ + corrupted = false; if (loc == sec->contents) - BFD_ASSERT (0); + corrupted = true; else { loc -= 4; if (loc != sec->contents) - { - BFD_ASSERT (0); - memset (sec->contents + 4, 0, loc - sec->contents); - loc = sec->contents; - } + corrupted = true; + } + if (corrupted) + { + /* xgettext:c-format */ + _bfd_error_handler (_("%pB: corrupted group section: `%pA'"), + abfd, sec); + bfd_set_error (bfd_error_bad_value); + *failedptr = true; + return; } H_PUT_32 (abfd, sec->flags & SEC_LINK_ONCE ? GRP_COMDAT : 0, loc); -- 2.49.0