[oe-commits] [openembedded-core] 12/51: binutils: CVE-2017-7224

git at git.openembedded.org git at git.openembedded.org
Sun Jan 7 17:11:21 UTC 2018


This is an automated email from the git hooks/post-receive script.

rpurdie pushed a commit to branch morty
in repository openembedded-core.

commit 54992e752e396fc5b3bc5b067cfc4741f1176bb3
Author: Thiruvadi Rajaraman <trajaraman at mvista.com>
AuthorDate: Mon Sep 4 13:56:15 2017 +0530

    binutils: CVE-2017-7224
    
    Source: git://sourceware.org/git/binutils-gdb.git
    MR: 74309
    Type: Security Fix
    Disposition: Backport from binutils-2_29-branch
    ChangeID: 640c2ad711ead368a65079a464c55368851e8744
    Description:
    
    Fix a seg-fault disassembling a corrupt binary.
    
        PR binutils/20892
        * aoutx.h (find_nearest_line): Handle the case where the function
          name is empty.
    
    Affects: <= 2.29
    Signed-off-by: Thiruvadi Rajaraman <trajaraman at mvista.com>
    Reviewed-by: Armin Kuster <akuster at mvista.com>
    Signed-off-by: Armin Kuster <akuster at mvista.com>
    Signed-off-by: Armin Kuster <akuster808 at gmail.com>
---
 meta/recipes-devtools/binutils/binutils-2.27.inc   |  1 +
 .../binutils/binutils/CVE-2017-7224.patch          | 48 ++++++++++++++++++++++
 2 files changed, 49 insertions(+)

diff --git a/meta/recipes-devtools/binutils/binutils-2.27.inc b/meta/recipes-devtools/binutils/binutils-2.27.inc
index 06c69b9..82b9be7 100644
--- a/meta/recipes-devtools/binutils/binutils-2.27.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.27.inc
@@ -60,6 +60,7 @@ SRC_URI = "\
      file://CVE-2017-12450_12452_12453_12454_12456_1.patch \
      file://CVE-2017-12450_12452_12453_12454_12456.patch \
      file://CVE-2017-7223.patch \
+     file://CVE-2017-7224.patch \
 "
 S  = "${WORKDIR}/git"
 
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2017-7224.patch b/meta/recipes-devtools/binutils/binutils/CVE-2017-7224.patch
new file mode 100644
index 0000000..fb9ce90
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2017-7224.patch
@@ -0,0 +1,48 @@
+commit e82ab856bb4689330c29fb9f1c57a8555b26380e
+Author: Nick Clifton <nickc at redhat.com>
+Date:   Thu Dec 1 10:49:39 2016 +0000
+
+    Fix a seg-fault disassembling a corrupt binary.
+    
+        PR binutils/20892
+        * aoutx.h (find_nearest_line): Handle the case where the function
+        name is empty.
+
+Upstream-Status: Backport
+
+CVE: CVE-2017-7224
+Signed-off-by: Thiruvadi Rajaraman <trajaraman at mvista.com>
+
+Index: git/bfd/ChangeLog
+===================================================================
+--- git.orig/bfd/ChangeLog	2017-09-04 12:54:37.513859864 +0530
++++ git/bfd/ChangeLog	2017-09-04 13:00:22.891753836 +0530
+@@ -120,6 +120,10 @@
+        * peicode.h (pe_ILF_object_p): Use strnlen to avoid running over
+        the end of the string buffer.
+ 
++       PR binutils/20892
++       * aoutx.h (find_nearest_line): Handle the case where the function
++       name is empty.
++
+ 2016-08-02  Nick Clifton  <nickc at redhat.com>
+ 
+ 	PR ld/17739
+Index: git/bfd/aoutx.h
+===================================================================
+--- git.orig/bfd/aoutx.h	2017-09-04 12:54:35.957851411 +0530
++++ git/bfd/aoutx.h	2017-09-04 12:57:50.634902163 +0530
+@@ -2819,6 +2819,13 @@
+       const char *function = func->name;
+       char *colon;
+ 
++      if (buf == NULL)
++       {
++         /* PR binutils/20892: In a corrupt input file func can be empty.  */
++         * functionname_ptr = NULL;
++         return TRUE;
++       }
++
+       /* The caller expects a symbol name.  We actually have a
+ 	 function name, without the leading underscore.  Put the
+ 	 underscore back in, so that the caller gets a symbol name.  */

-- 
To stop receiving notification emails like this one, please contact
the administrator of this repository.


More information about the Openembedded-commits mailing list