[oe-commits] [openembedded-core] 09/09: musl: Fix out of bounds data access in dlopen

git at git.openembedded.org git at git.openembedded.org
Fri Mar 1 07:16:08 UTC 2019


This is an automated email from the git hooks/post-receive script.

rpurdie pushed a commit to branch master-next
in repository openembedded-core.

commit c81a204f41bd018964d7ef096087ace5c78365c3
Author: Khem Raj <raj.khem at gmail.com>
AuthorDate: Thu Feb 28 19:21:12 2019 -0800

    musl: Fix out of bounds data access in dlopen
    
    Signed-off-by: Khem Raj <raj.khem at gmail.com>
    Signed-off-by: Richard Purdie <richard.purdie at linuxfoundation.org>
---
 meta/recipes-core/musl/musl/out_of_bounds_read.patch | 20 ++++++++++++++++++++
 meta/recipes-core/musl/musl_git.bb                   |  1 +
 2 files changed, 21 insertions(+)

diff --git a/meta/recipes-core/musl/musl/out_of_bounds_read.patch b/meta/recipes-core/musl/musl/out_of_bounds_read.patch
new file mode 100644
index 0000000..a681cc2
--- /dev/null
+++ b/meta/recipes-core/musl/musl/out_of_bounds_read.patch
@@ -0,0 +1,20 @@
+Fix out of bounds read
+
+self->dtv hasn't been extended yet
+
+Upstream-Status: Pending
+Signed-off-by: Khem Raj <raj.khem at gmail.com>
+
+diff --git a/ldso/dynlink.c b/ldso/dynlink.c
+index e2c3259f..b23ea0df 100644
+--- a/ldso/dynlink.c
++++ b/ldso/dynlink.c
+@@ -1374,7 +1376,7 @@ static void install_new_tls(void)
+ 	}
+ 	/* Install new dtls into the enlarged, uninstalled dtv copies. */
+ 	for (p=head; ; p=p->next) {
+-		if (!p->tls_id || self->dtv[p->tls_id]) continue;
++		if (p->tls_id <= old_cnt) continue;
+ 		unsigned char *mem = p->new_tls;
+ 		for (j=0; j<i; j++) {
+ 			unsigned char *new = mem;
diff --git a/meta/recipes-core/musl/musl_git.bb b/meta/recipes-core/musl/musl_git.bb
index f105227..6a72b7d 100644
--- a/meta/recipes-core/musl/musl_git.bb
+++ b/meta/recipes-core/musl/musl_git.bb
@@ -15,6 +15,7 @@ PV = "${BASEVER}+git${SRCPV}"
 SRC_URI = "git://git.musl-libc.org/musl \
            file://0001-Make-dynamic-linker-a-relative-symlink-to-libc.patch \
            file://0002-ldso-Use-syslibdir-and-libdir-as-default-pathes-to-l.patch \
+           file://out_of_bounds_read.patch \
           "
 
 S = "${WORKDIR}/git"

-- 
To stop receiving notification emails like this one, please contact
the administrator of this repository.


More information about the Openembedded-commits mailing list