d8307d
commit 5177d85b0c050a2333a0c4165c938dd422013d05
d8307d
Author: H.J. Lu <hjl.tools@gmail.com>
d8307d
Date:   Thu Jan 16 06:45:36 2020 -0800
d8307d
d8307d
    Clear GL(dl_initfirst) when freeing its link_map memory [BZ# 25396]
d8307d
    
d8307d
    We should clear GL(dl_initfirst) when freeing its link_map memory.
d8307d
    
d8307d
    Tested on Fedora 31/x86-64 with CET.
d8307d
    
d8307d
    Reviewed-by: Florian Weimer <fweimer@redhat.com>
d8307d
d8307d
diff --git a/elf/dl-close.c b/elf/dl-close.c
d8307d
index fa7f3e8174576e46..a9ecdff62dba88fb 100644
d8307d
--- a/elf/dl-close.c
d8307d
+++ b/elf/dl-close.c
d8307d
@@ -749,6 +749,10 @@ _dl_close_worker (struct link_map *map, bool force)
d8307d
 	  if (imap->l_runpath_dirs.dirs != (void *) -1)
d8307d
 	    free (imap->l_runpath_dirs.dirs);
d8307d
 
d8307d
+	  /* Clear GL(dl_initfirst) when freeing its link_map memory.  */
d8307d
+	  if (imap == GL(dl_initfirst))
d8307d
+	    GL(dl_initfirst) = NULL;
d8307d
+
d8307d
 	  free (imap);
d8307d
 	}
d8307d
     }