From f76d79580efea856298d9e5b9a91746be875f1b1 Mon Sep 17 00:00:00 2001 From: Nick Clifton Date: Thu, 21 Nov 2019 10:54:20 +0000 Subject: Fix potential buffer overrun in objcopy's note merging code. * objcopy.c (merge_gnu_build_notes): Allow for the possibility that the new notes might actually be larger than the original notes. --- binutils/objcopy.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) (limited to 'binutils/objcopy.c') diff --git a/binutils/objcopy.c b/binutils/objcopy.c index f682fbe..6e614b1 100644 --- a/binutils/objcopy.c +++ b/binutils/objcopy.c @@ -2460,7 +2460,9 @@ merge_gnu_build_notes (bfd * abfd, bfd_vma prev_start = 0; bfd_vma prev_end = 0; - new = new_contents = xmalloc (size); + /* Not sure how, but the notes might grow in size. + (eg see PR 1774507). Allow for this here. */ + new = new_contents = xmalloc (size * 2); for (pnote = pnotes, old = contents; pnote < pnotes_end; pnote ++) @@ -2527,8 +2529,11 @@ merge_gnu_build_notes (bfd * abfd, #endif new_size = new - new_contents; - memcpy (contents, new_contents, new_size); - size = new_size; + if (new_size < size) + { + memcpy (contents, new_contents, new_size); + size = new_size; + } free (new_contents); done: -- cgit v1.1