From patchwork Sun Jun 28 02:51:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alan Modra X-Patchwork-Id: 137955 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 1B2B94BA2E3D for ; Sun, 28 Jun 2026 02:51:41 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 1B2B94BA2E3D Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=eS9qPW3T X-Original-To: binutils@sourceware.org Delivered-To: binutils@sourceware.org Received: from mail-pl1-x633.google.com (mail-pl1-x633.google.com [IPv6:2607:f8b0:4864:20::633]) by sourceware.org (Postfix) with ESMTPS id CBE7C4BA2E2F for ; Sun, 28 Jun 2026 02:51:05 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org CBE7C4BA2E2F Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org CBE7C4BA2E2F Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::633 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782615066; cv=none; b=cMkoRi7XwfP3OKKdHbuk3HrWeGtT1BsrZFtmb9A0nknEqdjWjI0nOMulf0PT/hAgZu946TSQ7KqewLb9qGDgahhLVoixHLrMD3eCWR6wdvS0eO4icGsKeP43c//Y3sTomfJA/6OQjcnhuD0Z48i5cel1xXyPDd0688HBroTirkQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782615066; c=relaxed/simple; bh=BHNH3uOt+kKxGcnuZa2/iRVbn3Hu4OSSB2ge1ySWEu4=; h=DKIM-Signature:Date:From:To:Subject:Message-ID:MIME-Version; b=u6iFx87R4K6BkkhV1na7DGE8/134I8W2k18AK4AiWk1aCMY60m+asdubNfCswZFBC+ZAWj2fiqVs9KKYgF5vTfpWWOsrCfvvxxUbWwksQZV+6UBDMz6EgDkj4gQ4dpWiEn4dG6XZ2hV7eBjqTuHNHS9T16/6GszoAs0aPGyTYa0= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=eS9qPW3T DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org CBE7C4BA2E2F Received: by mail-pl1-x633.google.com with SMTP id d9443c01a7336-2c6b67d5fa1so12297835ad.2 for ; Sat, 27 Jun 2026 19:51:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782615064; x=1783219864; darn=sourceware.org; h=content-disposition:mime-version:message-id:subject:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=9miFAx0ae1VWH5V5kTU6CU4qyfR/dgkreRSslZ6oxp0=; b=eS9qPW3TDdVHqgv3SweKUle7V/nnXv6HAcfEJAlGhDdThCI6QqOcr8DKL0C/OGjgmX P2SfPa+wUcoDoZ7La1EjNb5PhiqjajIvncFFcP2gOwschaWWVUMwoiONpjGPK9K0bsz1 K/OTvmgq8atZM7WQGYm/mQTC1UT2OMhO7hh8ewi0NIoc3QvVmKPzG2sNGEhOJrXeCdty rXt6K7uaDe8HT4YlRi0vxQiLF5eDuE2sWErp7LGvU33VAvEuwJuDoHVXMjokUTcWDbFG oFFuuPoUDdVhPXrdMN/oNfAiN2HUJbvUOq9B0E3v9ulWIHaZklUUR7Z2SVbSMxyApPOe j7lQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782615064; x=1783219864; h=content-disposition:mime-version:message-id:subject:to:from:date :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=9miFAx0ae1VWH5V5kTU6CU4qyfR/dgkreRSslZ6oxp0=; b=KQg/f39oI5fzeHakLLGHCJcbT7IfpJJG2hdcQQ116EOCWuk8I87pkWsXriGm6qBWaH +b2DWgcZmFmW/m6Wa0nckQOOmFQLBA1O+m9SEZlwtk/YCmq/0G3LAsXdrUDTQzEqfV0P wW6GiDBB7yAMiESuoqswY26G+EqtDb2ABh2ilFsTfDwq9CFtV6KYJQOumZZ1AibP0bs0 cR9kQB7W4tSyDYFA/aCaSC7nWhEVFkKUVeWWoLGvZYSFvFdleZLUB6RzCQ0U5xMSBsSL E8c4+IzOPJX83YZeu1idWQAipNV83KCciDHvlvOvcUpoKDgb4e8M0+VgGMikOzdmcrLQ KHCw== X-Gm-Message-State: AOJu0YzcAMh3jHouTh6RM9gQQKzJs6ZuAdVDu5m8Et2Utr/Y2d23/5qU WDzYHe2c06gbW37TcKkcp1DNDOWAhzE2W8lJQaSptTIFZT7fjFQiZcMRYNcT0w== X-Gm-Gg: AfdE7cnm+cbQ8G4wDFpwyz611Z8rv3r2xQAslSd7ct/VZk0SgZe4nTwcokF7FF3b6KK 0UjISx0H1PMPJ/cbWu68cUymcAXsT0Q1OEE0Mh53Ztfqp3WF4aqvgBxmE+FB5yPaOacWoH6rvdg EEKkUtLjpCm3zHXWJK4NzdDvuWY6kDoEJPTexY2v/Kos0k3w2YyYLAuLtC0a7ciC7wWywvJwYdd N+pOelMGu9uMhM67Em74PmeWeuFlPf2WZwM6AbVr/ax32pxKE9fb2WLcl/SCS8G24XwT86wEg/F qEvnzf1J6Jf2N4nG0qwoevE5LIlKuEBJQKezZY88CFzsYsrl4wBufkRKL5++lH0AROc8c243TJ/ JYLwYe4856vnQ9OblGOJ7NI/mma8HyQExcf3xSW88VmQzgLYK4HqetDARHdFGCKycnqXOgCr2Tz J/6rbAV0uPX7KRcImj1l4K6ULYBA== X-Received: by 2002:a17:902:c405:b0:2c6:ab74:985e with SMTP id d9443c01a7336-2c7fc767c25mr117377455ad.25.1782615064151; Sat, 27 Jun 2026 19:51:04 -0700 (PDT) Received: from squeak.grove.modra.org ([2406:3400:51d:8cc0:4821:c461:6ca9:467c]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2c9d88663acsm7524225ad.44.2026.06.27.19.51.03 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 27 Jun 2026 19:51:03 -0700 (PDT) Received: by squeak.grove.modra.org (Postfix, from userid 1000) id 461E211419CF; Sun, 28 Jun 2026 12:21:01 +0930 (ACST) Date: Sun, 28 Jun 2026 12:21:01 +0930 From: Alan Modra To: binutils@sourceware.org Subject: asan: buffer overflow in m32r_elf_generic_reloc Message-ID: MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-3029.7 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: binutils@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Binutils mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: binutils-bounces~patchwork=sourceware.org@sourceware.org The existing sanity check didn't take into account the size of the reloc field. So a field that started before the end of section, but extended past it, accessed past the end of the contents buffer. * elf32-m32r.c (m32r_elf_generic_reloc): Properly check reloc offset. (m32r_elf_do_10_pcrel_reloc): Likewise. diff --git a/bfd/elf32-m32r.c b/bfd/elf32-m32r.c index 80a1b1eaa7a..1219d9b04fc 100644 --- a/bfd/elf32-m32r.c +++ b/bfd/elf32-m32r.c @@ -98,7 +98,7 @@ m32r_elf_do_10_pcrel_reloc (bfd *abfd, bfd_reloc_status_type status; /* Sanity check the address (offset in section). */ - if (offset > bfd_get_section_limit (abfd, input_section)) + if (!bfd_reloc_offset_in_range (howto, abfd, input_section, offset)) return bfd_reloc_outofrange; relocation = symbol_value + addend; @@ -192,7 +192,8 @@ m32r_elf_generic_reloc (bfd *input_bfd, a section relative addend which is wrong. */ /* Sanity check the address (offset in section). */ - if (reloc_entry->address > bfd_get_section_limit (input_bfd, input_section)) + if (!bfd_reloc_offset_in_range (reloc_entry->howto, input_bfd, + input_section, reloc_entry->address)) return bfd_reloc_outofrange; ret = bfd_reloc_ok;