mirror of
https://git.yoctoproject.org/poky
synced 2026-07-29 13:17:44 +02:00
binutils: fix CVE-2025-69649, and CVE-2025-69652
CVE-2025-69649: Null pointer dereference in readelf before 2.46 results in segfault when processing a crafted ELF binary with malformed header fields. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed. CVE-2025-69652: Null pointer dereference in readelf when processing a crafted ELF binary with malformed DWARF abbrev or debug information which leads to SIGABORT. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service. (From OE-Core rev: 86dd1306e350c4cd3b36a39254d6f17587960a60) Signed-off-by: Roland Kovacs <roland.kovacs@est.tech> [YC: patches are referenced in the NVD database: https://nvd.nist.gov/vuln/detail/CVE-2025-69649 https://nvd.nist.gov/vuln/detail/CVE-2025-69652 ] Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
committed by
Paul Barker
parent
5f7a875f6d
commit
72b30efa58
@@ -74,6 +74,8 @@ SRC_URI = "\
|
||||
file://0030-CVE-2025-11840.patch \
|
||||
file://CVE-2025-69644-CVE-2025-69647.patch \
|
||||
file://CVE-2025-69648.patch \
|
||||
file://CVE-2025-69649.patch \
|
||||
file://CVE-2025-69652.patch \
|
||||
file://CVE-2026-6846.patch \
|
||||
"
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
44
meta/recipes-devtools/binutils/binutils/CVE-2025-69649.patch
Normal file
44
meta/recipes-devtools/binutils/binutils/CVE-2025-69649.patch
Normal file
@@ -0,0 +1,44 @@
|
||||
From 37c8055eed3178a46417045dda63db7af21fd046 Mon Sep 17 00:00:00 2001
|
||||
From: Alan Modra <amodra@gmail.com>
|
||||
Date: Mon, 8 Dec 2025 15:58:33 +1030
|
||||
Subject: [PATCH] PR 33697, fuzzer segfault
|
||||
|
||||
PR 33697
|
||||
* readelf.c (process_relocs): Don't segfault on no sections.
|
||||
|
||||
CVE: CVE-2025-69649
|
||||
Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66]
|
||||
|
||||
Note:
|
||||
The difference between this patch on v2.42 and upstream v2.46 is due to
|
||||
the loop body printing the relocations in-line, which then in commit
|
||||
8e8d0b63ff15896cc2c228c01f18dfcf2a4a9305 have been factored out to a
|
||||
separate 'display_relocations()' function.
|
||||
|
||||
See: [https://sourceware.org/git/?p=binutils-gdb.git;a=blobdiff;f=binutils/readelf.c;h=fa0de3a7e0d9c2acc18fe047a7019e09f1ce3894;hp=c1006480b7bc3e83dd87fb20d215342375614af9;hb=8e8d0b63ff15896cc2c228c01f18dfcf2a4a9305;hpb=31c21e2c13d85793b525f74aa911eb28700ed89c]
|
||||
|
||||
Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
|
||||
---
|
||||
binutils/readelf.c | 6 +++---
|
||||
1 file changed, 3 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/binutils/readelf.c b/binutils/readelf.c
|
||||
index 5e4ad6ea6ad..8c1987ffaec 100644
|
||||
--- a/binutils/readelf.c
|
||||
+++ b/binutils/readelf.c
|
||||
@@ -8961,9 +8961,9 @@ process_relocs (Filedata * filedata)
|
||||
size_t i;
|
||||
bool found = false;
|
||||
|
||||
- for (i = 0, section = filedata->section_headers;
|
||||
- i < filedata->file_header.e_shnum;
|
||||
- i++, section++)
|
||||
+ section = filedata->section_headers;
|
||||
+ if (section != NULL)
|
||||
+ for (i = 0; i < filedata->file_header.e_shnum; i++, section++)
|
||||
{
|
||||
if ( section->sh_type != SHT_RELA
|
||||
&& section->sh_type != SHT_REL
|
||||
--
|
||||
2.34.1
|
||||
|
||||
39
meta/recipes-devtools/binutils/binutils/CVE-2025-69652.patch
Normal file
39
meta/recipes-devtools/binutils/binutils/CVE-2025-69652.patch
Normal file
@@ -0,0 +1,39 @@
|
||||
From cb4f8fe24cc86a9f050be4cf9c619940f632ea6a Mon Sep 17 00:00:00 2001
|
||||
From: Alan Modra <amodra@gmail.com>
|
||||
Date: Mon, 8 Dec 2025 16:04:44 +1030
|
||||
Subject: [PATCH] PR 33701, abort in byte_get_little_endian
|
||||
|
||||
PR 33701
|
||||
* dwarf.c (process_debug_info): Set debug_info_p NULL when
|
||||
DEBUG_INFO_UNAVAILABLE.
|
||||
|
||||
CVE: CVE-2025-69652
|
||||
Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01]
|
||||
|
||||
Signed-off-by: Roland Kovacs <roland.kovacs@est.tech>
|
||||
---
|
||||
binutils/dwarf.c | 8 +++++---
|
||||
1 file changed, 5 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/binutils/dwarf.c b/binutils/dwarf.c
|
||||
index 615e051b2bf..13b11b46e41 100644
|
||||
--- a/binutils/dwarf.c
|
||||
+++ b/binutils/dwarf.c
|
||||
@@ -4222,9 +4222,11 @@ process_debug_info (struct dwarf_section * section,
|
||||
break;
|
||||
}
|
||||
|
||||
- debug_info *debug_info_p =
|
||||
- (debug_information && unit < alloc_num_debug_info_entries)
|
||||
- ? debug_information + unit : NULL;
|
||||
+ debug_info *debug_info_p = NULL;
|
||||
+ if (debug_information
|
||||
+ && num_debug_info_entries != DEBUG_INFO_UNAVAILABLE
|
||||
+ && unit < alloc_num_debug_info_entries)
|
||||
+ debug_info_p = debug_information + unit;
|
||||
|
||||
assert (!debug_info_p
|
||||
|| (debug_info_p->num_loc_offsets
|
||||
--
|
||||
2.34.1
|
||||
|
||||
Reference in New Issue
Block a user