PR22887, null pointer dereference in aout_32_swap_std_reloc_out

Message ID 20180228114837.GA3812@bubble.grove.modra.org
State New
Headers show
Series
  • PR22887, null pointer dereference in aout_32_swap_std_reloc_out
Related show

Commit Message

Alan Modra Feb. 28, 2018, 11:48 a.m.
PR 22887
	* aoutx.h (swap_std_reloc_in): Correct r_index bound check.


-- 
Alan Modra
Australia Development Lab, IBM

Patch

diff --git a/bfd/aoutx.h b/bfd/aoutx.h
index 4cadbfb..525e560 100644
--- a/bfd/aoutx.h
+++ b/bfd/aoutx.h
@@ -2289,10 +2289,12 @@  NAME (aout, swap_std_reloc_in) (bfd *abfd,
   if (r_baserel)
     r_extern = 1;
 
-  if (r_extern && r_index > symcount)
+  if (r_extern && r_index >= symcount)
     {
       /* We could arrange to return an error, but it might be useful
-	 to see the file even if it is bad.  */
+	 to see the file even if it is bad.  FIXME: Of course this
+	 means that objdump -r *doesn't* see the actual reloc, and
+	 objcopy silently writes a different reloc.  */
       r_extern = 0;
       r_index = N_ABS;
     }