Prevent memory exhaustion from a corrupt PE binary with an overlarge number of relocs.
PR 21440 * objdump.c (dump_relocs_in_section): Check for an excessive number of relocs before attempting to dump them.
This commit is contained in:
parent
d050f7d7f4
commit
39ff1b79f6
|
@ -1,3 +1,9 @@
|
||||||
|
2017-05-02 Nick Clifton <nickc@redhat.com>
|
||||||
|
|
||||||
|
PR 21440
|
||||||
|
* objdump.c (dump_relocs_in_section): Check for an excessive
|
||||||
|
number of relocs before attempting to dump them.
|
||||||
|
|
||||||
2017-05-01 Alan Modra <amodra@gmail.com>
|
2017-05-01 Alan Modra <amodra@gmail.com>
|
||||||
|
|
||||||
* objcopy.c (merge_gnu_build_notes): Correct code deleting
|
* objcopy.c (merge_gnu_build_notes): Correct code deleting
|
||||||
|
|
|
@ -3379,6 +3379,14 @@ dump_relocs_in_section (bfd *abfd,
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if ((bfd_get_file_flags (abfd) & (BFD_IN_MEMORY | BFD_LINKER_CREATED)) == 0
|
||||||
|
&& relsize > get_file_size (bfd_get_filename (abfd)))
|
||||||
|
{
|
||||||
|
printf (" (too many: 0x%x)\n", section->reloc_count);
|
||||||
|
bfd_set_error (bfd_error_file_truncated);
|
||||||
|
bfd_fatal (bfd_get_filename (abfd));
|
||||||
|
}
|
||||||
|
|
||||||
relpp = (arelent **) xmalloc (relsize);
|
relpp = (arelent **) xmalloc (relsize);
|
||||||
relcount = bfd_canonicalize_reloc (abfd, section, relpp, syms);
|
relcount = bfd_canonicalize_reloc (abfd, section, relpp, syms);
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue