From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-pj1-x102e.google.com (mail-pj1-x102e.google.com [IPv6:2607:f8b0:4864:20::102e]) by sourceware.org (Postfix) with ESMTPS id DF5573858D32 for ; Sun, 19 Mar 2023 11:51:07 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org DF5573858D32 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pj1-x102e.google.com with SMTP id d13so9596005pjh.0 for ; Sun, 19 Mar 2023 04:51:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; t=1679226666; h=content-disposition:mime-version:message-id:subject:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=S2IjCfeJRr/pRQBtUNUHeAz+/9BTQ36YauDI9qlHGs8=; b=ZNqFrbFSI1B6f32abowTy0LRWC/D48OS/MxNAsNCCtMM5UjkA05zzOwRPkTaYsYtdy om/r6KnDSOnfAlDsSpFI02B1uXXb4Ra4wEci9+0ZoolBj/nOgxh7jF81BzM/WP29PvrC 2kFSxa7nr0AaDItfHA8hD+e3FRcx2F3zTa+p9l+xJBdo3QrnLjQOAM6D6dIG9snAZckI 6Wu9/tx1kGV2iLsC1IoWiAVNHYbHbClJQtLN3LeBS0kT7LkFDjjVSGBUDxBD4Z/OPl4j nb5E30LGKvrbv6nALYcUPZXdSAfHilmOqA9jOaa+2Dz9js6Ojsvjy3RmFxnxpo2gced7 p2Ug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1679226666; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=S2IjCfeJRr/pRQBtUNUHeAz+/9BTQ36YauDI9qlHGs8=; b=snnBNGf9wDTVIsm6yxFypFPD6wkzKfq8oVZJXyuR0yVRuuOaU2HT2vV2IGQKQpG1+V SO0LX+919uWx9IIc0NhYWv2qo4GR6yfZExDUtsf7eTE3YriBedkV+b+M2v509+l8A8QZ vdlUHrQKCct1jCtl2aq7wdZhzRDlTOTBnzJNHTE9WxzhSfLhl/OlzT8tdtsKL5EsRltN ZPU3f2kOqH18VxRS5wBAriFU3qDK1UTCI1lBjxsq83hbgBVehlGFvTUVkeQ8gfi1ifiX fqL7nBCfnN9G3R4d3x3HkjJ2K29SK25UZv3oFDq3OGNt4wZT76Ji1s/Ef7bVgY0lMiB+ tsrQ== X-Gm-Message-State: AO0yUKV+3bWw0O2KUxzzv/iklW33t0CJ06XSG876ExU2xiOmHPpNhd55 C8t0HquSFLTAjg7bdiFf9wvcgROAu0I= X-Google-Smtp-Source: AK7set97cCBQBIFv79w4KMknM5yxPF3EduSWnvq9R+zh+/aFBfeApDgQ6kzf/6aXS8E/41A4omW7ew== X-Received: by 2002:a17:90a:7345:b0:23f:78d6:b5cc with SMTP id j5-20020a17090a734500b0023f78d6b5ccmr4981751pjs.38.1679226666125; Sun, 19 Mar 2023 04:51:06 -0700 (PDT) Received: from squeak.grove.modra.org (158.106.96.58.static.exetel.com.au. [58.96.106.158]) by smtp.gmail.com with ESMTPSA id 60-20020a17090a09c200b00234465cd2a7sm4167892pjo.56.2023.03.19.04.51.04 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Mar 2023 04:51:05 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id AC40F1142CE7; Sun, 19 Mar 2023 22:21:02 +1030 (ACDT) Date: Sun, 19 Mar 2023 22:21:02 +1030 From: Alan Modra To: binutils@sourceware.org Subject: ctf segfaults Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Spam-Status: No, score=-3035.2 required=5.0 tests=BAYES_00,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM,GIT_PATCH_0,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS,TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org List-Id: PR 30228 PR 30229 * ctf-open.c (ctf_bufopen_internal): Check for NULL cts_data. * ctf-archive.c (ctf_arc_bufpreamble, ctf_arc_bufopen): Likewise. diff --git a/libctf/ctf-archive.c b/libctf/ctf-archive.c index abae90da113..54c49b3edbb 100644 --- a/libctf/ctf-archive.c +++ b/libctf/ctf-archive.c @@ -402,8 +402,9 @@ ctf_arc_symsect_endianness (ctf_archive_t *arc, int little_endian) const ctf_preamble_t * ctf_arc_bufpreamble (const ctf_sect_t *ctfsect) { - if (ctfsect->cts_size > sizeof (uint64_t) && - (le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC)) + if (ctfsect->cts_data != NULL + && ctfsect->cts_size > sizeof (uint64_t) + && (le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC)) { struct ctf_archive *arc = (struct ctf_archive *) ctfsect->cts_data; return (const ctf_preamble_t *) ((char *) arc + le64toh (arc->ctfa_ctfs) @@ -424,8 +425,9 @@ ctf_arc_bufopen (const ctf_sect_t *ctfsect, const ctf_sect_t *symsect, int is_archive; ctf_dict_t *fp = NULL; - if (ctfsect->cts_size > sizeof (uint64_t) && - (le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC)) + if (ctfsect->cts_data != NULL + && ctfsect->cts_size > sizeof (uint64_t) + && (le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC)) { /* The archive is mmappable, so this operation is trivial. diff --git a/libctf/ctf-open.c b/libctf/ctf-open.c index 5bcf0dd9b76..35f635b6559 100644 --- a/libctf/ctf-open.c +++ b/libctf/ctf-open.c @@ -1354,7 +1354,8 @@ ctf_bufopen_internal (const ctf_sect_t *ctfsect, const ctf_sect_t *symsect, if (strsect != NULL && strsect->cts_data == NULL) return (ctf_set_open_errno (errp, ECTF_STRBAD)); - if (ctfsect->cts_size < sizeof (ctf_preamble_t)) + if (ctfsect->cts_data == NULL + || ctfsect->cts_size < sizeof (ctf_preamble_t)) return (ctf_set_open_errno (errp, ECTF_NOCTFBUF)); pp = (const ctf_preamble_t *) ctfsect->cts_data; -- Alan Modra Australia Development Lab, IBM