From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-pl1-x62c.google.com (mail-pl1-x62c.google.com [IPv6:2607:f8b0:4864:20::62c]) by sourceware.org (Postfix) with ESMTPS id 593683856DE2 for ; Wed, 26 Oct 2022 07:27:37 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org 593683856DE2 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-x62c.google.com with SMTP id p3so12289262pld.10 for ; Wed, 26 Oct 2022 00:27:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-disposition:mime-version:message-id:subject:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=29+dgplm/FMaxpNiHgLin3S1igjMmluklwW7f4iOGrw=; b=JTGjZYZZNX3XFDC2tVOGIFWG9rsz0haCDTpkSmqSqx7tHVZqsiW0QGof2B8wwFKaHD utlFNfmPNjIB426J5NXSM2qWS2Kxgeki99yEKJkeQQrQ4NouhlDaXAEP3/TbYGa4fOpx RWkQFiMn0H1X3SB7op1Z341eZHx9IFwbVkZJqy84TOfJ3HE/8Gehz0mDXTc+5F1+1/Cy iMDKui2FczVWWXTux3aHTM/M3dfUOGrb+8WfwUEaKijHMMzeK7fxBb1YqQvNia3Ggql4 pYQqlIrbsAKDKVbO4MXU1610RQBF4lJHBc+hyKHfU9IQjH0blIWMO+3t6PFSgQorVJDR FcIw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=29+dgplm/FMaxpNiHgLin3S1igjMmluklwW7f4iOGrw=; b=D8I1Vyr6WNZ3qPjViad4lrG2iUHJTd9ZxwTT4FXyhq7WyVsqLOlKI7Bhf0oCpJTFhy IFNnEt5RSmpOMKU4ncD8pf1NngkPAoU21dHfd0NvNRw4udk26+wsUrCFcMgTjvoahCDk VADGR0O2eC9pFijDkN1BBjVGk/dfeGKoxJMX3lF8meH5Z359uBe3Y8xyRbhdeVaDCURl y+MvjiaMGFEZU8v8/gzkOi07zOweIq37bIc9NRUMbWCvYVPGwoRPpxhxXOKDnFx3ajCx MqV5RCZ5m0qQGkHteZdxmFsA7In184bamhKETr1EZjoBN1wn7YCTHFWAcVI4zZxpRj74 k+8A== X-Gm-Message-State: ACrzQf0a0H5oQEjKcziib2M7gRzPJMEw9s8PpsJMvtWCorMssgxKYmmG qi4I7MhG29LdozRSeZFxkHFH3gB6cpU= X-Google-Smtp-Source: AMsMyM6mQTza+nJ13KBCN54BBJtJVStI3hGpXpi1XAhhbiH4m6oLB1iNlKtoN5l5fw4akNn7wAskIQ== X-Received: by 2002:a17:902:8212:b0:186:a260:50a0 with SMTP id x18-20020a170902821200b00186a26050a0mr15613362pln.157.1666769256019; Wed, 26 Oct 2022 00:27:36 -0700 (PDT) Received: from squeak.grove.modra.org ([2406:3400:51d:8cc0:a3ea:1d22:1394:10bb]) by smtp.gmail.com with ESMTPSA id m15-20020a17090a158f00b00212d4c50647sm628316pja.36.2022.10.26.00.27.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Oct 2022 00:27:31 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id B08121141EBA; Wed, 26 Oct 2022 17:57:23 +1030 (ACDT) Date: Wed, 26 Oct 2022 17:57:23 +1030 From: Alan Modra To: binutils@sourceware.org Subject: buffer overflow in _bfd_XX_print_ce_compressed_pdata Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Spam-Status: No, score=-3035.6 required=5.0 tests=BAYES_00,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM,GIT_PATCH_0,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS,TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org List-Id: More fuzzed fun. * peXXigen.c (_bfd_XX_print_ce_compressed_pdata): Use smaller of virt_size and bfd section size as limit of function table. diff --git a/bfd/peXXigen.c b/bfd/peXXigen.c index c5a7f7bf7ac..0232a63d558 100644 --- a/bfd/peXXigen.c +++ b/bfd/peXXigen.c @@ -2026,6 +2026,8 @@ _bfd_XX_print_ce_compressed_pdata (bfd * abfd, void * vfile) } start = 0; + if (stop > datasize) + stop = datasize; for (i = start; i < stop; i += onaline) { -- Alan Modra Australia Development Lab, IBM