[binutils-gdb] asan: buffer overflow in elf32_dlx_relocate26
Alan Modra via Binutils-cvs <[email protected]> Sun, 28 Jun 2026 02:53:15 +0000 (GMT)
| Newsgroups | gmane.comp.gnu.binutils.cvs |
|---|---|
| Message-ID | <[email protected]> |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=114e3aae2b7e34057c8909301eaf78c15687e8e5 commit 114e3aae2b7e34057c8909301eaf78c15687e8e5 Author: Alan Modra <[email protected]> Date: Sun Jun 28 09:11:46 2026 +0930 asan: buffer overflow in elf32_dlx_relocate26 * elf32-dlx.c (elf32_dlx_relocate26): Sanity check reloc offset. (elf32_dlx_relocate16): Likewise. (_bfd_dlx_elf_hi16_reloc): Likewise, and remove ineffective existing check. Diff: --- bfd/elf32-dlx.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/bfd/elf32-dlx.c b/bfd/elf32-dlx.c index 2dfeb4d7390..0f9a49695d7 100644 --- a/bfd/elf32-dlx.c +++ b/bfd/elf32-dlx.c @@ -77,6 +77,10 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd, return bfd_reloc_ok; } + if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, + input_section, reloc_entry->address)) + return bfd_reloc_outofrange; + ret = bfd_reloc_ok; if (bfd_is_und_section (symbol->section) @@ -89,9 +93,6 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd, relocation += reloc_entry->addend; relocation += bfd_get_16 (abfd, (bfd_byte *)data + reloc_entry->address); - if (reloc_entry->address > bfd_get_section_limit (abfd, input_section)) - return bfd_reloc_outofrange; - bfd_put_16 (abfd, (short)((relocation >> 16) & 0xFFFF), (bfd_byte *)data + reloc_entry->address); @@ -143,6 +144,10 @@ elf32_dlx_relocate16 (bfd *abfd, return bfd_reloc_undefined; } + if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, + input_section, reloc_entry->address)) + return bfd_reloc_outofrange; + insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address); allignment = 1 << (input_section->output_section->alignment_power - 1); vallo = insn & 0x0000FFFF; @@ -206,6 +211,10 @@ elf32_dlx_relocate26 (bfd *abfd, return bfd_reloc_undefined; } + if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd, + input_section, reloc_entry->address)) + return bfd_reloc_outofrange; + insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address); allignment = 1 << (input_section->output_section->alignment_power - 1); vallo = insn & 0x03FFFFFF;