|
|
a094f6 |
commit 5860e3f883597cf6b8a937547015394edc1e8784
|
|
|
a094f6 |
Author: Nick Clifton <nickc@redhat.com>
|
|
|
a094f6 |
Date: Mon Dec 22 20:59:00 2014 +0000
|
|
|
a094f6 |
|
|
|
a094f6 |
More fixes for memory access violations exposed by fuzzed binaries.
|
|
|
a094f6 |
|
|
|
a094f6 |
PR binutils/17512
|
|
|
a094f6 |
* archive.c (do_slurp_bsd_armap): Return if the parsed_size is
|
|
|
a094f6 |
zero.
|
|
|
a094f6 |
(bfd_slurp_armap): Zero terminate the name.
|
|
|
a094f6 |
(bfd_generic_stat_arch_elt): If there is no header, fail.
|
|
|
a094f6 |
* elf32-arc.c (arc_info_to_howto_rel): Replace BFD_ASSERT with
|
|
|
a094f6 |
error message.
|
|
|
a094f6 |
* elf32-avr.c (avr_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-cr16c.c (elf_cr16c_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-cris.c (cris_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-d10v.c (d10v_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-d30v.c (d30v_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-dlx.c (dlx_rtype_to_howto): Likewise.
|
|
|
a094f6 |
* elf32-epiphany.c (epiphany_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-fr30.c (fr30_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-frv.c (frv_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-i960.c (elf32_i960_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-ip2k.c (ip2k_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-iq2000.c (iq2000_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-lm32.c (lm32_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-m32c.c (m32c_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-m32r.c (m32r_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-m68hc11.c (m68hc11_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-m68hc12.c (m68hc11_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-mep.c (mep_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-metag.c (metag_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-moxie.c (moxie_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-msp430.c (msp430_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-mt.c (mt_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-nds32.c (nds32_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-or1k.c (or1k_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-rl78.c (rl78_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-rx.c (rx_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-v850.c (v850_elf_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-visium.c (visium_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf32-xgate.c (xgate_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
* elf32-xtensa.c (elf_xtensa_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf64-mmix.c (mmix_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
* elf64-x86-64.c (elf_x86_64_reloc_type_lookup): Likewise.
|
|
|
a094f6 |
* elfnn-aarch64.c (elfNN_aarch64_bfd_reloc_from_type): Likewise.
|
|
|
a094f6 |
* elf64-sparc.c (elf64_sparc_slurp_one_reloc_table): Add range
|
|
|
a094f6 |
checking of reloc symbol index.
|
|
|
a094f6 |
* mach-o.c (bfd_mach_o_canonicalize_one_reloc): If no symbols have
|
|
|
a094f6 |
been provided then set the reloc's symbol to undefined.
|
|
|
a094f6 |
* reloc.c (bfd_generic_get_relocated_section_contents): Add range
|
|
|
a094f6 |
checking of the reloc to be applied.
|
|
|
a094f6 |
* versados.c (process_otr): Add more range checks.
|
|
|
a094f6 |
(versados_canonicalize_reloc): If the section is unknown, set the
|
|
|
a094f6 |
symbol to undefined.
|
|
|
a094f6 |
* vms-alpha.c (_bfd_vms_slurp_eisd): Add range checks.
|
|
|
a094f6 |
(alpha_vms_object_p): Likewise.
|
|
|
a094f6 |
|
|
|
a094f6 |
### a/bfd/ChangeLog
|
|
|
a094f6 |
### b/bfd/ChangeLog
|
|
|
a094f6 |
## -1,3 +1,57 @@
|
|
|
a094f6 |
+2014-12-22 Nick Clifton <nickc@redhat.com>
|
|
|
a094f6 |
+
|
|
|
a094f6 |
+ PR binutils/17512
|
|
|
a094f6 |
+ * archive.c (do_slurp_bsd_armap): Return if the parsed_size is
|
|
|
a094f6 |
+ zero.
|
|
|
a094f6 |
+ (bfd_slurp_armap): Zero terminate the name.
|
|
|
a094f6 |
+ (bfd_generic_stat_arch_elt): If there is no header, fail.
|
|
|
a094f6 |
+ * elf32-arc.c (arc_info_to_howto_rel): Replace BFD_ASSERT with
|
|
|
a094f6 |
+ error message.
|
|
|
a094f6 |
+ * elf32-avr.c (avr_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-cr16c.c (elf_cr16c_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-cris.c (cris_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-d10v.c (d10v_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-d30v.c (d30v_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-dlx.c (dlx_rtype_to_howto): Likewise.
|
|
|
a094f6 |
+ * elf32-epiphany.c (epiphany_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-fr30.c (fr30_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-frv.c (frv_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-i960.c (elf32_i960_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-ip2k.c (ip2k_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-iq2000.c (iq2000_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-lm32.c (lm32_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-m32c.c (m32c_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-m32r.c (m32r_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-m68hc11.c (m68hc11_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-m68hc12.c (m68hc11_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-mep.c (mep_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-metag.c (metag_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-moxie.c (moxie_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-msp430.c (msp430_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-mt.c (mt_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-nds32.c (nds32_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-or1k.c (or1k_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-rl78.c (rl78_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-rx.c (rx_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-v850.c (v850_elf_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-visium.c (visium_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf32-xgate.c (xgate_info_to_howto_rel): Likewise.
|
|
|
a094f6 |
+ * elf32-xtensa.c (elf_xtensa_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf64-mmix.c (mmix_info_to_howto_rela): Likewise.
|
|
|
a094f6 |
+ * elf64-x86-64.c (elf_x86_64_reloc_type_lookup): Likewise.
|
|
|
a094f6 |
+ * elfnn-aarch64.c (elfNN_aarch64_bfd_reloc_from_type): Likewise.
|
|
|
a094f6 |
+ * elf64-sparc.c (elf64_sparc_slurp_one_reloc_table): Add range
|
|
|
a094f6 |
+ checking of reloc symbol index.
|
|
|
a094f6 |
+ * mach-o.c (bfd_mach_o_canonicalize_one_reloc): If no symbols have
|
|
|
a094f6 |
+ been provided then set the reloc's symbol to undefined.
|
|
|
a094f6 |
+ * reloc.c (bfd_generic_get_relocated_section_contents): Add range
|
|
|
a094f6 |
+ checking of the reloc to be applied.
|
|
|
a094f6 |
+ * versados.c (process_otr): Add more range checks.
|
|
|
a094f6 |
+ (versados_canonicalize_reloc): If the section is unknown, set the
|
|
|
a094f6 |
+ symbol to undefined.
|
|
|
a094f6 |
+ * vms-alpha.c (_bfd_vms_slurp_eisd): Add range checks.
|
|
|
a094f6 |
+ (alpha_vms_object_p): Likewise.
|
|
|
a094f6 |
+
|
|
|
a094f6 |
2014-12-18 Richard Henderson <rth@redhat.com>
|
|
|
a094f6 |
|
|
|
a094f6 |
* elf32-ppc.c (ELF_COMMONPAGESIZE): Set to 64k.
|
|
|
a094f6 |
--- a/bfd/archive.c
|
|
|
a094f6 |
+++ b/bfd/archive.c
|
|
|
a094f6 |
@@ -902,6 +902,9 @@ do_slurp_bsd_armap (bfd *abfd)
|
|
|
a094f6 |
return FALSE;
|
|
|
a094f6 |
parsed_size = mapdata->parsed_size;
|
|
|
a094f6 |
free (mapdata);
|
|
|
a094f6 |
+ /* PR 17512: file: 883ff754. */
|
|
|
a094f6 |
+ if (parsed_size == 0)
|
|
|
a094f6 |
+ return FALSE;
|
|
|
a094f6 |
|
|
|
a094f6 |
raw_armap = (bfd_byte *) bfd_zalloc (abfd, parsed_size);
|
|
|
a094f6 |
if (raw_armap == NULL)
|
|
|
a094f6 |
@@ -917,7 +920,6 @@ do_slurp_bsd_armap (bfd *abfd)
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
ardata->symdef_count = H_GET_32 (abfd, raw_armap) / BSD_SYMDEF_SIZE;
|
|
|
a094f6 |
-
|
|
|
a094f6 |
if (ardata->symdef_count * BSD_SYMDEF_SIZE >
|
|
|
a094f6 |
parsed_size - BSD_SYMDEF_COUNT_SIZE)
|
|
|
a094f6 |
{
|
|
|
a094f6 |
@@ -1138,6 +1140,7 @@ bfd_slurp_armap (bfd *abfd)
|
|
|
a094f6 |
return FALSE;
|
|
|
a094f6 |
if (bfd_seek (abfd, -(file_ptr) (sizeof (hdr) + 20), SEEK_CUR) != 0)
|
|
|
a094f6 |
return FALSE;
|
|
|
a094f6 |
+ extname[20] = 0;
|
|
|
a094f6 |
if (CONST_STRNEQ (extname, "__.SYMDEF SORTED")
|
|
|
a094f6 |
|| CONST_STRNEQ (extname, "__.SYMDEF"))
|
|
|
a094f6 |
return do_slurp_bsd_armap (abfd);
|
|
|
a094f6 |
@@ -1971,7 +1974,9 @@ bfd_generic_stat_arch_elt (bfd *abfd, struct stat *buf)
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
hdr = arch_hdr (abfd);
|
|
|
a094f6 |
-
|
|
|
a094f6 |
+ /* PR 17512: file: 3d9e9fe9. */
|
|
|
a094f6 |
+ if (hdr == NULL)
|
|
|
a094f6 |
+ return -1;
|
|
|
a094f6 |
#define foo(arelt, stelt, size) \
|
|
|
a094f6 |
buf->stelt = strtol (hdr->arelt, &aloser, size); \
|
|
|
a094f6 |
if (aloser == hdr->arelt) \
|
|
|
a094f6 |
--- a/bfd/elf32-arc.c
|
|
|
a094f6 |
+++ b/bfd/elf32-arc.c
|
|
|
a094f6 |
@@ -172,7 +172,11 @@ arc_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_ARC_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_ARC_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid ARC reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_arc_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-avr.c
|
|
|
a094f6 |
+++ b/bfd/elf32-avr.c
|
|
|
a094f6 |
@@ -859,7 +859,11 @@ avr_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_AVR_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_AVR_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid AVR reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_avr_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-cr16c.c
|
|
|
a094f6 |
+++ b/bfd/elf32-cr16c.c
|
|
|
a094f6 |
@@ -180,7 +180,11 @@ elf_cr16c_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
{
|
|
|
a094f6 |
unsigned int r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) RINDEX_16C_MAX);
|
|
|
a094f6 |
+ if (r_type >= RINDEX_16C_MAX)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A; invalid CR16C reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-cris.c
|
|
|
a094f6 |
+++ b/bfd/elf32-cris.c
|
|
|
a094f6 |
@@ -461,7 +461,11 @@ cris_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
enum elf_cris_reloc_type r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_CRIS_max);
|
|
|
a094f6 |
+ if (r_type >= R_CRIS_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid CRIS reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & cris_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-d10v.c
|
|
|
a094f6 |
+++ b/bfd/elf32-d10v.c
|
|
|
a094f6 |
@@ -228,7 +228,11 @@ d10v_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_D10V_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_D10V_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid D10V reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_d10v_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-d30v.c
|
|
|
a094f6 |
+++ b/bfd/elf32-d30v.c
|
|
|
a094f6 |
@@ -516,7 +516,11 @@ d30v_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_D30V_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_D30V_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid D30V reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_d30v_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
@@ -530,7 +534,11 @@ d30v_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_D30V_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_D30V_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid D30V reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_d30v_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-dlx.c
|
|
|
a094f6 |
+++ b/bfd/elf32-dlx.c
|
|
|
a094f6 |
@@ -546,7 +546,11 @@ dlx_rtype_to_howto (unsigned int r_type)
|
|
|
a094f6 |
case R_DLX_RELOC_16_LO:
|
|
|
a094f6 |
return & elf_dlx_reloc_16_lo;
|
|
|
a094f6 |
default:
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_DLX_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_DLX_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("Invalid DLX reloc number: %d"), r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
return & dlx_elf_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
}
|
|
|
a094f6 |
--- a/bfd/elf32-epiphany.c
|
|
|
a094f6 |
+++ b/bfd/elf32-epiphany.c
|
|
|
a094f6 |
@@ -370,6 +370,11 @@ epiphany_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_EPIPHANY_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid Epiphany reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & epiphany_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-fr30.c
|
|
|
a094f6 |
+++ b/bfd/elf32-fr30.c
|
|
|
a094f6 |
@@ -375,7 +375,11 @@ fr30_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_FR30_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_FR30_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid FR30 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & fr30_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-frv.c
|
|
|
a094f6 |
+++ b/bfd/elf32-frv.c
|
|
|
a094f6 |
@@ -2557,6 +2557,11 @@ frv_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
break;
|
|
|
a094f6 |
|
|
|
a094f6 |
default:
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_FRV_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid FRV reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & elf32_frv_howto_table [r_type];
|
|
|
a094f6 |
break;
|
|
|
a094f6 |
}
|
|
|
a094f6 |
--- a/bfd/elf32-i960.c
|
|
|
a094f6 |
+++ b/bfd/elf32-i960.c
|
|
|
a094f6 |
@@ -132,7 +132,13 @@ elf32_i960_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
enum elf_i960_reloc_type type;
|
|
|
a094f6 |
|
|
|
a094f6 |
type = (enum elf_i960_reloc_type) ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (type < R_960_max);
|
|
|
a094f6 |
+
|
|
|
a094f6 |
+ /* PR 17521: file: 9609b8d6. */
|
|
|
a094f6 |
+ if (type >= R_960_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A; invalid i960 reloc number: %d"), abfd, type);
|
|
|
a094f6 |
+ type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
|
|
|
a094f6 |
cache_ptr->howto = &elf_howto_table[(int) type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
--- a/bfd/elf32-ip2k.c
|
|
|
a094f6 |
+++ b/bfd/elf32-ip2k.c
|
|
|
a094f6 |
@@ -1239,6 +1239,11 @@ ip2k_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_IP2K_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid IP2K reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & ip2k_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-iq2000.c
|
|
|
a094f6 |
+++ b/bfd/elf32-iq2000.c
|
|
|
a094f6 |
@@ -435,6 +435,11 @@ iq2000_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
break;
|
|
|
a094f6 |
|
|
|
a094f6 |
default:
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_IQ2000_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid IQ2000 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & iq2000_elf_howto_table [r_type];
|
|
|
a094f6 |
break;
|
|
|
a094f6 |
}
|
|
|
a094f6 |
--- a/bfd/elf32-lm32.c
|
|
|
a094f6 |
+++ b/bfd/elf32-lm32.c
|
|
|
a094f6 |
@@ -588,7 +588,11 @@ lm32_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_LM32_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_LM32_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid LM32 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &lm32_elf_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-m32c.c
|
|
|
a094f6 |
+++ b/bfd/elf32-m32c.c
|
|
|
a094f6 |
@@ -297,7 +297,11 @@ m32c_info_to_howto_rela
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_M32C_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_M32C_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid M32C reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & m32c_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-m32r.c
|
|
|
a094f6 |
+++ b/bfd/elf32-m32r.c
|
|
|
a094f6 |
@@ -1280,7 +1280,11 @@ m32r_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (ELF32_R_TYPE(dst->r_info) <= (unsigned int) R_M32R_GNU_VTENTRY);
|
|
|
a094f6 |
+ if (r_type > (unsigned int) R_M32R_GNU_VTENTRY)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid M32R reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &m32r_elf_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-m68hc11.c
|
|
|
a094f6 |
+++ b/bfd/elf32-m68hc11.c
|
|
|
a094f6 |
@@ -384,7 +384,11 @@ m68hc11_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_M68HC11_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_M68HC11_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid M68HC11 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_m68hc11_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-m68hc12.c
|
|
|
a094f6 |
+++ b/bfd/elf32-m68hc12.c
|
|
|
a094f6 |
@@ -504,7 +504,11 @@ m68hc11_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_M68HC11_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_M68HC11_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid M68HC12 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_m68hc11_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-mep.c
|
|
|
a094f6 |
+++ b/bfd/elf32-mep.c
|
|
|
a094f6 |
@@ -400,6 +400,11 @@ mep_info_to_howto_rela
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
+ if (r_type >= R_MEP_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid MEP reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & mep_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-metag.c
|
|
|
a094f6 |
+++ b/bfd/elf32-metag.c
|
|
|
a094f6 |
@@ -896,7 +896,11 @@ metag_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_METAG_MAX);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_METAG_MAX)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid METAG reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & elf_metag_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-moxie.c
|
|
|
a094f6 |
+++ b/bfd/elf32-moxie.c
|
|
|
a094f6 |
@@ -131,7 +131,11 @@ moxie_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_MOXIE_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_MOXIE_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid Moxie reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & moxie_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
#--- a/bfd/elf32-msp430.c
|
|
|
a094f6 |
#+++ b/bfd/elf32-msp430.c
|
|
|
a094f6 |
#@@ -617,12 +617,20 @@ msp430_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
#
|
|
|
a094f6 |
# if (uses_msp430x_relocs (abfd))
|
|
|
a094f6 |
# {
|
|
|
a094f6 |
#- BFD_ASSERT (r_type < (unsigned int) R_MSP430x_max);
|
|
|
a094f6 |
#+ if (r_type >= (unsigned int) R_MSP430x_max)
|
|
|
a094f6 |
#+ {
|
|
|
a094f6 |
#+ _bfd_error_handler (_("%A: invalid MSP430X reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
#+ r_type = 0;
|
|
|
a094f6 |
#+ }
|
|
|
a094f6 |
# cache_ptr->howto = elf_msp430x_howto_table + r_type;
|
|
|
a094f6 |
# return;
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
#
|
|
|
a094f6 |
#- BFD_ASSERT (r_type < (unsigned int) R_MSP430_max);
|
|
|
a094f6 |
#+ if (r_type >= (unsigned int) R_MSP430_max)
|
|
|
a094f6 |
#+ {
|
|
|
a094f6 |
#+ _bfd_error_handler (_("%A: invalid MSP430 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
#+ r_type = 0;
|
|
|
a094f6 |
#+ }
|
|
|
a094f6 |
# cache_ptr->howto = &elf_msp430_howto_table[r_type];
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
#
|
|
|
a094f6 |
--- a/bfd/elf32-mt.c
|
|
|
a094f6 |
+++ b/bfd/elf32-mt.c
|
|
|
a094f6 |
@@ -236,6 +236,11 @@ mt_info_to_howto_rela
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_MT_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid MT reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = & mt_elf_howto_table [r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
#--- a/bfd/elf32-nds32.c
|
|
|
a094f6 |
#+++ b/bfd/elf32-nds32.c
|
|
|
a094f6 |
#@@ -2965,7 +2965,11 @@ nds32_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED, arelent *cache_ptr,
|
|
|
a094f6 |
# enum elf_nds32_reloc_type r_type;
|
|
|
a094f6 |
#
|
|
|
a094f6 |
# r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
#- BFD_ASSERT (ELF32_R_TYPE (dst->r_info) <= R_NDS32_GNU_VTENTRY);
|
|
|
a094f6 |
#+ if (r_type > R_NDS32_GNU_VTENTRY)
|
|
|
a094f6 |
#+ {
|
|
|
a094f6 |
#+ _bfd_error_handler (_("%A: invalid NDS32 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
#+ r_type = 0;
|
|
|
a094f6 |
#+ }
|
|
|
a094f6 |
# cache_ptr->howto = bfd_elf32_bfd_reloc_type_table_lookup (r_type);
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
#
|
|
|
a094f6 |
#--- a/bfd/elf32-or1k.c
|
|
|
a094f6 |
#+++ b/bfd/elf32-or1k.c
|
|
|
a094f6 |
#@@ -738,7 +738,11 @@ or1k_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
# unsigned int r_type;
|
|
|
a094f6 |
#
|
|
|
a094f6 |
# r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
#- BFD_ASSERT (r_type < (unsigned int) R_OR1K_max);
|
|
|
a094f6 |
#+ if (r_type >= (unsigned int) R_OR1K_max)
|
|
|
a094f6 |
#+ {
|
|
|
a094f6 |
#+ _bfd_error_handler (_("%A: invalid OR1K reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
#+ r_type = 0;
|
|
|
a094f6 |
#+ }
|
|
|
a094f6 |
# cache_ptr->howto = & or1k_elf_howto_table[r_type];
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
#
|
|
|
a094f6 |
--- a/bfd/elf32-rl78.c
|
|
|
a094f6 |
+++ b/bfd/elf32-rl78.c
|
|
|
a094f6 |
@@ -276,7 +276,11 @@ rl78_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_RL78_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_RL78_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid RL78 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = rl78_elf_howto_table + r_type;
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-rx.c
|
|
|
a094f6 |
+++ b/bfd/elf32-rx.c
|
|
|
a094f6 |
@@ -307,7 +307,11 @@ rx_info_to_howto_rela (bfd * abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_RX_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_RX_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid RX reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = rx_elf_howto_table + r_type;
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-v850.c
|
|
|
a094f6 |
+++ b/bfd/elf32-v850.c
|
|
|
a094f6 |
@@ -1896,7 +1896,11 @@ v850_elf_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_V850_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_V850_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid V850 reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &v850_elf_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
#--- a/bfd/elf32-visium.c
|
|
|
a094f6 |
#+++ b/bfd/elf32-visium.c
|
|
|
a094f6 |
#@@ -501,6 +501,11 @@ visium_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED, arelent *cache_ptr,
|
|
|
a094f6 |
# break;
|
|
|
a094f6 |
#
|
|
|
a094f6 |
# default:
|
|
|
a094f6 |
#+ if (r_type >= (unsigned int) R_VISIUM_max)
|
|
|
a094f6 |
#+ {
|
|
|
a094f6 |
#+ _bfd_error_handler (_("%A: invalid Visium reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
#+ r_type = 0;
|
|
|
a094f6 |
#+ }
|
|
|
a094f6 |
# cache_ptr->howto = &visium_elf_howto_table[r_type];
|
|
|
a094f6 |
# break;
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
--- a/bfd/elf32-xgate.c
|
|
|
a094f6 |
+++ b/bfd/elf32-xgate.c
|
|
|
a094f6 |
@@ -422,7 +422,11 @@ xgate_info_to_howto_rel (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT(r_type < (unsigned int) R_XGATE_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_XGATE_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid XGate reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_xgate_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf32-xtensa.c
|
|
|
a094f6 |
+++ b/bfd/elf32-xtensa.c
|
|
|
a094f6 |
@@ -479,7 +479,11 @@ elf_xtensa_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
{
|
|
|
a094f6 |
unsigned int r_type = ELF32_R_TYPE (dst->r_info);
|
|
|
a094f6 |
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_XTENSA_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_XTENSA_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid XTENSA reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf64-mmix.c
|
|
|
a094f6 |
+++ b/bfd/elf64-mmix.c
|
|
|
a094f6 |
@@ -1259,7 +1259,11 @@ mmix_info_to_howto_rela (bfd *abfd ATTRIBUTE_UNUSED,
|
|
|
a094f6 |
unsigned int r_type;
|
|
|
a094f6 |
|
|
|
a094f6 |
r_type = ELF64_R_TYPE (dst->r_info);
|
|
|
a094f6 |
- BFD_ASSERT (r_type < (unsigned int) R_MMIX_max);
|
|
|
a094f6 |
+ if (r_type >= (unsigned int) R_MMIX_max)
|
|
|
a094f6 |
+ {
|
|
|
a094f6 |
+ _bfd_error_handler (_("%A: invalid MMIX reloc number: %d"), abfd, r_type);
|
|
|
a094f6 |
+ r_type = 0;
|
|
|
a094f6 |
+ }
|
|
|
a094f6 |
cache_ptr->howto = &elf_mmix_howto_table[r_type];
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
--- a/bfd/elf64-sparc.c
|
|
|
a094f6 |
+++ b/bfd/elf64-sparc.c
|
|
|
a094f6 |
@@ -97,7 +97,9 @@ elf64_sparc_slurp_one_reloc_table (bfd *abfd, asection *asect,
|
|
|
a094f6 |
else
|
|
|
a094f6 |
relent->address = rela.r_offset - asect->vma;
|
|
|
a094f6 |
|
|
|
a094f6 |
- if (ELF64_R_SYM (rela.r_info) == STN_UNDEF)
|
|
|
a094f6 |
+ if (ELF64_R_SYM (rela.r_info) == STN_UNDEF
|
|
|
a094f6 |
+ /* PR 17512: file: 996185f8. */
|
|
|
a094f6 |
+ || ELF64_R_SYM (rela.r_info) > bfd_get_symcount (abfd))
|
|
|
a094f6 |
relent->sym_ptr_ptr = bfd_abs_section_ptr->symbol_ptr_ptr;
|
|
|
a094f6 |
else
|
|
|
a094f6 |
{
|
|
|
a094f6 |
--- a/bfd/elf64-x86-64.c
|
|
|
a094f6 |
+++ b/bfd/elf64-x86-64.c
|
|
|
a094f6 |
@@ -302,7 +302,7 @@ elf_x86_64_reloc_type_lookup (bfd *abfd,
|
|
|
a094f6 |
return elf_x86_64_rtype_to_howto (abfd,
|
|
|
a094f6 |
x86_64_reloc_map[i].elf_reloc_val);
|
|
|
a094f6 |
}
|
|
|
a094f6 |
- return 0;
|
|
|
a094f6 |
+ return NULL;
|
|
|
a094f6 |
}
|
|
|
a094f6 |
|
|
|
a094f6 |
static reloc_howto_type *
|
|
|
a094f6 |
#--- a/bfd/elfnn-aarch64.c
|
|
|
a094f6 |
#+++ b/bfd/elfnn-aarch64.c
|
|
|
a094f6 |
#@@ -1431,6 +1431,14 @@ elfNN_aarch64_bfd_reloc_from_type (unsigned int r_type)
|
|
|
a094f6 |
# if (r_type == R_AARCH64_NONE || r_type == R_AARCH64_NULL)
|
|
|
a094f6 |
# return BFD_RELOC_AARCH64_NONE;
|
|
|
a094f6 |
#
|
|
|
a094f6 |
#+ /* PR 17512: file: b371e70a. */
|
|
|
a094f6 |
#+ if (r_type >= R_AARCH64_end)
|
|
|
a094f6 |
#+ {
|
|
|
a094f6 |
#+ _bfd_error_handler (_("Invalid AArch64 reloc number: %d"), r_type);
|
|
|
a094f6 |
#+ bfd_set_error (bfd_error_bad_value);
|
|
|
a094f6 |
#+ return BFD_RELOC_AARCH64_NONE;
|
|
|
a094f6 |
#+ }
|
|
|
a094f6 |
#+
|
|
|
a094f6 |
# return BFD_RELOC_AARCH64_RELOC_START + offsets[r_type];
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
#
|
|
|
a094f6 |
#--- a/bfd/mach-o.c
|
|
|
a094f6 |
#+++ b/bfd/mach-o.c
|
|
|
a094f6 |
#@@ -1352,6 +1352,8 @@ bfd_mach_o_canonicalize_one_reloc (bfd *abfd,
|
|
|
a094f6 |
# /* PR 17512: file: 8396-1185-0.004. */
|
|
|
a094f6 |
# if (bfd_get_symcount (abfd) > 0 && num > bfd_get_symcount (abfd))
|
|
|
a094f6 |
# sym = bfd_und_section_ptr->symbol_ptr_ptr;
|
|
|
a094f6 |
#+ else if (syms == NULL)
|
|
|
a094f6 |
#+ sym = bfd_und_section_ptr->symbol_ptr_ptr;
|
|
|
a094f6 |
# else
|
|
|
a094f6 |
# /* An external symbol number. */
|
|
|
a094f6 |
# sym = syms + num;
|
|
|
a094f6 |
--- a/bfd/reloc.c
|
|
|
a094f6 |
+++ b/bfd/reloc.c
|
|
|
a094f6 |
@@ -7623,6 +7623,10 @@ bfd_generic_get_relocated_section_contents (bfd *abfd,
|
|
|
a094f6 |
(*parent)->howto = &none_howto;
|
|
|
a094f6 |
r = bfd_reloc_ok;
|
|
|
a094f6 |
}
|
|
|
a094f6 |
+ /* PR 17512: file: c146ab8b. */
|
|
|
a094f6 |
+ else if ((*parent)->address * bfd_octets_per_byte (abfd)
|
|
|
a094f6 |
+ >= bfd_get_section_size (input_section))
|
|
|
a094f6 |
+ r = bfd_reloc_outofrange;
|
|
|
a094f6 |
else
|
|
|
a094f6 |
r = bfd_perform_relocation (input_bfd,
|
|
|
a094f6 |
*parent,
|
|
|
a094f6 |
#--- a/bfd/versados.c
|
|
|
a094f6 |
#+++ b/bfd/versados.c
|
|
|
a094f6 |
#@@ -373,10 +373,17 @@ process_otr (bfd *abfd, struct ext_otr *otr, int pass)
|
|
|
a094f6 |
# | (otr->map[3] << 0);
|
|
|
a094f6 |
#
|
|
|
a094f6 |
# struct esdid *esdid = &EDATA (abfd, otr->esdid - 1);
|
|
|
a094f6 |
#- unsigned char *contents = esdid->contents;
|
|
|
a094f6 |
#+ unsigned char *contents;
|
|
|
a094f6 |
# bfd_boolean need_contents = FALSE;
|
|
|
a094f6 |
#- unsigned int dst_idx = esdid->pc;
|
|
|
a094f6 |
#-
|
|
|
a094f6 |
#+ unsigned int dst_idx;
|
|
|
a094f6 |
#+
|
|
|
a094f6 |
#+ /* PR 17512: file: ac7da425. */
|
|
|
a094f6 |
#+ if (otr->esdid == 0)
|
|
|
a094f6 |
#+ return;
|
|
|
a094f6 |
#+
|
|
|
a094f6 |
#+ contents = esdid->contents;
|
|
|
a094f6 |
#+ dst_idx = esdid->pc;
|
|
|
a094f6 |
#+
|
|
|
a094f6 |
# for (shift = ((unsigned long) 1 << 31); shift && srcp < endp; shift >>= 1)
|
|
|
a094f6 |
# {
|
|
|
a094f6 |
# if (bits & shift)
|
|
|
a094f6 |
#@@ -399,7 +406,7 @@ process_otr (bfd *abfd, struct ext_otr *otr, int pass)
|
|
|
a094f6 |
#
|
|
|
a094f6 |
# if (pass == 1)
|
|
|
a094f6 |
# need_contents = TRUE;
|
|
|
a094f6 |
#- else if (contents)
|
|
|
a094f6 |
#+ else if (contents && dst_idx < esdid->section->size - sizeinwords * 2)
|
|
|
a094f6 |
# for (j = 0; j < sizeinwords * 2; j++)
|
|
|
a094f6 |
# {
|
|
|
a094f6 |
# contents[dst_idx + (sizeinwords * 2) - j - 1] = val;
|
|
|
a094f6 |
#@@ -421,10 +428,13 @@ process_otr (bfd *abfd, struct ext_otr *otr, int pass)
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
# else
|
|
|
a094f6 |
# {
|
|
|
a094f6 |
#- arelent *n =
|
|
|
a094f6 |
#- EDATA (abfd, otr->esdid - 1).section->relocation + rn;
|
|
|
a094f6 |
#- n->address = dst_idx;
|
|
|
a094f6 |
#+ arelent *n;
|
|
|
a094f6 |
#
|
|
|
a094f6 |
#+ /* PR 17512: file: 54f733e0. */
|
|
|
a094f6 |
#+ if (EDATA (abfd, otr->esdid - 1).section == NULL)
|
|
|
a094f6 |
#+ continue;
|
|
|
a094f6 |
#+ n = EDATA (abfd, otr->esdid - 1).section->relocation + rn;
|
|
|
a094f6 |
#+ n->address = dst_idx;
|
|
|
a094f6 |
# n->sym_ptr_ptr = (asymbol **) (size_t) id;
|
|
|
a094f6 |
# n->addend = 0;
|
|
|
a094f6 |
# n->howto = versados_howto_table + ((j & 1) * 2) + (sizeinwords - 1);
|
|
|
a094f6 |
#@@ -798,7 +808,11 @@ versados_canonicalize_reloc (bfd *abfd,
|
|
|
a094f6 |
# /* Section relative thing. */
|
|
|
a094f6 |
# struct esdid *e = &EDATA (abfd, esdid - 1);
|
|
|
a094f6 |
#
|
|
|
a094f6 |
#- src[count].sym_ptr_ptr = e->section->symbol_ptr_ptr;
|
|
|
a094f6 |
#+ /* PR 17512: file:cd92277c. */
|
|
|
a094f6 |
#+ if (e->section)
|
|
|
a094f6 |
#+ src[count].sym_ptr_ptr = e->section->symbol_ptr_ptr;
|
|
|
a094f6 |
#+ else
|
|
|
a094f6 |
#+ src[count].sym_ptr_ptr = bfd_und_section_ptr->symbol_ptr_ptr;
|
|
|
a094f6 |
# }
|
|
|
a094f6 |
# /* PR 17512: file:3757-2936-0.004. */
|
|
|
a094f6 |
# else if ((unsigned) (esdid - ES_BASE) >= bfd_get_symcount (abfd))
|
|
|
a094f6 |
--- a/bfd/vms-alpha.c
|
|
|
a094f6 |
+++ b/bfd/vms-alpha.c
|
|
|
a094f6 |
@@ -521,9 +521,11 @@ _bfd_vms_slurp_eisd (bfd *abfd, unsigned int offset)
|
|
|
a094f6 |
asection *section;
|
|
|
a094f6 |
flagword bfd_flags;
|
|
|
a094f6 |
|
|
|
a094f6 |
+ /* PR 17512: file: 3d9e9fe9. */
|
|
|
a094f6 |
+ if (offset >= PRIV (recrd.rec_size))
|
|
|
a094f6 |
+ return FALSE;
|
|
|
a094f6 |
eisd = (struct vms_eisd *)(PRIV (recrd.rec) + offset);
|
|
|
a094f6 |
rec_size = bfd_getl32 (eisd->eisdsize);
|
|
|
a094f6 |
-
|
|
|
a094f6 |
if (rec_size == 0)
|
|
|
a094f6 |
break;
|
|
|
a094f6 |
|
|
|
a094f6 |
@@ -2527,6 +2529,9 @@ alpha_vms_object_p (bfd *abfd)
|
|
|
a094f6 |
/* Reset the record pointer. */
|
|
|
a094f6 |
PRIV (recrd.rec) = buf;
|
|
|
a094f6 |
|
|
|
a094f6 |
+ /* PR 17512: file: 7d7c57c2. */
|
|
|
a094f6 |
+ if (PRIV (recrd.rec_size) < sizeof (struct vms_eihd))
|
|
|
a094f6 |
+ goto error_ret;
|
|
|
a094f6 |
vms_debug2 ((2, "file type is image\n"));
|
|
|
a094f6 |
|
|
|
a094f6 |
if (_bfd_vms_slurp_eihd (abfd, &eisd_offset, &eihs_offset) != TRUE)
|