[PATCH] elf: prevent NULL-dereference in _dl_map_new_object()

Florian Weimer fweimer@redhat.com
Fri Jul 18 15:52:13 GMT 2025


* Anastasia Belova:

> On 7/1/25 2:17 PM, Florian Weimer wrote:
>> * Anastasia Belova:
>>
>>> If name = NULL going to no_file leads to NULL-dereference
>>> while calling __strdup(name). Exit the program instead.
>>>
>>> Signed-off-by: Anastasia Belova <abelova@astralinux.ru>
>>> ---
>>>   elf/dl-load.c | 6 ++----
>>>   1 file changed, 2 insertions(+), 4 deletions(-)
>>>
>>> diff --git a/elf/dl-load.c b/elf/dl-load.c
>>> index 6e26ef0583..5f56ac22e6 100644
>>> --- a/elf/dl-load.c
>>> +++ b/elf/dl-load.c
>>> @@ -1955,7 +1955,8 @@ _dl_map_new_object (struct link_map *loader, const char *name,
>>>         if (name == NULL)
>>>   	{
>>>   	  fd = -1;
>>> -	  goto no_file;
>>> +	  _dl_signal_error (errno, before, NULL,
>>> +			  N_("cannot find origname"));
>>>   	}
>>>         if (before != name && strcmp (before, name) != 0)
>>>   	origname = before;
>>> @@ -2127,9 +2128,6 @@ _dl_map_new_object (struct link_map *loader, const char *name,
>>>   	}
>>>       }
>>>   -#ifdef SHARED
>>> - no_file:
>>> -#endif
>>>     /* In case the LOADER information has only been provided to get to
>>>        the appropriate RUNPATH/RPATH information we do not need it
>>>        anymore.  */
>> I think the error message should be "auditor declined to load object" or
>> something like it.  (It's not a memory allocation error or other error
>> condition.)
>
>
> Should I form the second version or you will fix it while applying?

Please send a second version.  Ideally this would have test that checks
for the error message.  We do not have many tests for la_objsearch yet,
but elf/tst-audit11 might be a good starting point.

Thanks,
Florian



More information about the Libc-alpha mailing list