Prevent memory exhaustion from a corrupt PE binary with an overlarge number of relocs.
PR 21440 * objdump.c (dump_relocs_in_section): Check for an excessive number of relocs before attempting to dump them.
This commit is contained in:
parent
d050f7d7f4
commit
39ff1b79f6
@ -1,3 +1,9 @@
|
||||
2017-05-02 Nick Clifton <nickc@redhat.com>
|
||||
|
||||
PR 21440
|
||||
* objdump.c (dump_relocs_in_section): Check for an excessive
|
||||
number of relocs before attempting to dump them.
|
||||
|
||||
2017-05-01 Alan Modra <amodra@gmail.com>
|
||||
|
||||
* objcopy.c (merge_gnu_build_notes): Correct code deleting
|
||||
|
@ -3379,6 +3379,14 @@ dump_relocs_in_section (bfd *abfd,
|
||||
return;
|
||||
}
|
||||
|
||||
if ((bfd_get_file_flags (abfd) & (BFD_IN_MEMORY | BFD_LINKER_CREATED)) == 0
|
||||
&& relsize > get_file_size (bfd_get_filename (abfd)))
|
||||
{
|
||||
printf (" (too many: 0x%x)\n", section->reloc_count);
|
||||
bfd_set_error (bfd_error_file_truncated);
|
||||
bfd_fatal (bfd_get_filename (abfd));
|
||||
}
|
||||
|
||||
relpp = (arelent **) xmalloc (relsize);
|
||||
relcount = bfd_canonicalize_reloc (abfd, section, relpp, syms);
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user