From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-pl1-x62d.google.com (mail-pl1-x62d.google.com [IPv6:2607:f8b0:4864:20::62d]) by sourceware.org (Postfix) with ESMTPS id CC6CB3945062 for ; Fri, 20 Mar 2020 02:08:59 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.3.2 sourceware.org CC6CB3945062 Received: by mail-pl1-x62d.google.com with SMTP id t16so1856112plr.8 for ; Thu, 19 Mar 2020 19:08:59 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:subject:message-id:mime-version :content-disposition:user-agent; bh=fB4uevGVvFoAWftkDDGoszSfS168VeLMN+fvEzmyDB8=; b=Nq88IWmZAwNCtMnpf8J0ylyeVUTi4ThiVL0nfTUQOxNAEA3btzHe/mXkJrrXdasnBu ROtWh1+ufJ/TdzNF4UFocYQ6p/LlfjGYA5ccjeoxQD9z4RuUbh/kSpjRTsTn+crerrXa VWAncdCiEqtTpiq4AsxAtEhpkaCcTwqqxuUwf2tcsGXxRjyEPQjGzZhQqwHT8iblCy2c kzSJwH2Gzx2txVolHowKEyzXMSqqaKh1f0GAoAzJQhT9yxQgJDvufk3v8Y+2230o6xV6 K+l4U3Krdgow4JfVxudcJ6gVJKJTHBwsVDrpau33k/39F6uGRnwpBDlEGV7qTGduSwxa ujBg== X-Gm-Message-State: ANhLgQ1UEc686NCt4ArSoPLFj5fz6mgjBJu9+HVRCYglR0y/yIJqR6uC gXOqmMppcIRbTLxLxZ5kGNVXgK+xOVc= X-Google-Smtp-Source: ADFU+vu69i/zfwCxlakr3VqPeH4ShpHxRrbNnjPwMkiLkITRvAE2cYLB1EYyqIoXFTnVgaxBEZLxBw== X-Received: by 2002:a17:90b:124a:: with SMTP id gx10mr6900708pjb.117.1584670138694; Thu, 19 Mar 2020 19:08:58 -0700 (PDT) Received: from bubble.grove.modra.org (158.106.96.58.static.exetel.com.au. [58.96.106.158]) by smtp.gmail.com with ESMTPSA id z16sm3702982pfr.138.2020.03.19.19.08.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 19 Mar 2020 19:08:58 -0700 (PDT) Received: by bubble.grove.modra.org (Postfix, from userid 1000) id CAED380856; Fri, 20 Mar 2020 12:38:54 +1030 (ACDT) Date: Fri, 20 Mar 2020 12:38:54 +1030 From: Alan Modra To: binutils@sourceware.org Subject: XCOFF uninitialized read Message-ID: <20200320020854.GI4583@bubble.grove.modra.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.9.4 (2018-02-28) X-Spam-Status: No, score=-25.2 required=5.0 tests=DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, GIT_PATCH_1, GIT_PATCH_2, GIT_PATCH_3, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS autolearn=ham autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on server2.sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Mar 2020 02:09:00 -0000 * coff-rs6000.c (_bfd_xcoff_slurp_armap): Ensure size is large enough to read number of symbols. diff --git a/bfd/coff-rs6000.c b/bfd/coff-rs6000.c index 2dd68e08c3..bf87596a4f 100644 --- a/bfd/coff-rs6000.c +++ b/bfd/coff-rs6000.c @@ -1260,9 +1260,9 @@ _bfd_xcoff_slurp_armap (bfd *abfd) return FALSE; GET_VALUE_IN_FIELD (sz, hdr.size, 10); - if (sz == (bfd_size_type) -1) + if (sz + 1 < 5) { - bfd_set_error (bfd_error_no_memory); + bfd_set_error (bfd_error_bad_value); return FALSE; } @@ -1322,9 +1322,9 @@ _bfd_xcoff_slurp_armap (bfd *abfd) return FALSE; GET_VALUE_IN_FIELD (sz, hdr.size, 10); - if (sz == (bfd_size_type) -1) + if (sz + 1 < 9) { - bfd_set_error (bfd_error_no_memory); + bfd_set_error (bfd_error_bad_value); return FALSE; } -- Alan Modra Australia Development Lab, IBM