mirror of
https://git.yoctoproject.org/poky
synced 2026-02-25 02:49:40 +01:00
See: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=89395 (From OE-Core rev: cef180de3684491f1ac4180ddbcc102121222181) Signed-off-by: Anuj Mittal <anuj.mittal@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
166 lines
5.7 KiB
Diff
166 lines
5.7 KiB
Diff
From c1202057eb9161a86af27d867703235fee7b7555 Mon Sep 17 00:00:00 2001
|
|
From: Nick Clifton <nickc@redhat.com>
|
|
Date: Wed, 10 Apr 2019 15:49:36 +0100
|
|
Subject: [PATCH] Pull in patch for libiberty that fixes a stack exhaustion bug
|
|
when demangling a pathalogically constructed mangled name.
|
|
|
|
PR 89394
|
|
* cp-demangle.c (cplus_demangle_fill_name): Reject negative
|
|
lengths.
|
|
(d_count_templates_scopes): Replace num_templates and num_scopes
|
|
parameters with a struct d_print_info pointer parameter. Adjust
|
|
body of the function accordingly. Add recursion counter and check
|
|
that the recursion limit is not reached.
|
|
(d_print_init): Pass dpi parameter to d_count_templates_scopes.
|
|
Reset recursion counter afterwards, unless the recursion limit was
|
|
reached.
|
|
|
|
CVE: CVE-2019-9071
|
|
CVE: CVE-2019-9070
|
|
Upstream-Status: Backport
|
|
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
|
|
---
|
|
ChangeLog | 16 ++++++++++++++
|
|
libiberty/cp-demangle.c | 48 ++++++++++++++++++++++-------------------
|
|
2 files changed, 42 insertions(+), 22 deletions(-)
|
|
|
|
diff --git a/ChangeLog b/ChangeLog
|
|
index cd631a15b6..4df3aaa62c 100644
|
|
--- a/ChangeLog
|
|
+++ b/ChangeLog
|
|
@@ -1,3 +1,19 @@
|
|
+2019-04-10 Nick Clifton <nickc@redhat.com>
|
|
+
|
|
+ * libiberty: Sync with gcc. Bring in:
|
|
+ 2019-04-10 Nick Clifton <nickc@redhat.com>
|
|
+
|
|
+ PR 89394
|
|
+ * cp-demangle.c (cplus_demangle_fill_name): Reject negative
|
|
+ lengths.
|
|
+ (d_count_templates_scopes): Replace num_templates and num_scopes
|
|
+ parameters with a struct d_print_info pointer parameter. Adjust
|
|
+ body of the function accordingly. Add recursion counter and check
|
|
+ that the recursion limit is not reached.
|
|
+ (d_print_init): Pass dpi parameter to d_count_templates_scopes.
|
|
+ Reset recursion counter afterwards, unless the recursion limit was
|
|
+ reached.
|
|
+
|
|
2018-06-24 Nick Clifton <nickc@redhat.com>
|
|
|
|
2.32 branch created.
|
|
diff --git a/libiberty/cp-demangle.c b/libiberty/cp-demangle.c
|
|
index b34b485692..779b4e763a 100644
|
|
--- a/libiberty/cp-demangle.c
|
|
+++ b/libiberty/cp-demangle.c
|
|
@@ -861,7 +861,7 @@ CP_STATIC_IF_GLIBCPP_V3
|
|
int
|
|
cplus_demangle_fill_name (struct demangle_component *p, const char *s, int len)
|
|
{
|
|
- if (p == NULL || s == NULL || len == 0)
|
|
+ if (p == NULL || s == NULL || len <= 0)
|
|
return 0;
|
|
p->d_printing = 0;
|
|
p->type = DEMANGLE_COMPONENT_NAME;
|
|
@@ -4061,7 +4061,7 @@ d_growable_string_callback_adapter (const char *s, size_t l, void *opaque)
|
|
are larger than the actual numbers encountered. */
|
|
|
|
static void
|
|
-d_count_templates_scopes (int *num_templates, int *num_scopes,
|
|
+d_count_templates_scopes (struct d_print_info *dpi,
|
|
const struct demangle_component *dc)
|
|
{
|
|
if (dc == NULL)
|
|
@@ -4081,13 +4081,13 @@ d_count_templates_scopes (int *num_templates, int *num_scopes,
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_TEMPLATE:
|
|
- (*num_templates)++;
|
|
+ dpi->num_copy_templates++;
|
|
goto recurse_left_right;
|
|
|
|
case DEMANGLE_COMPONENT_REFERENCE:
|
|
case DEMANGLE_COMPONENT_RVALUE_REFERENCE:
|
|
if (d_left (dc)->type == DEMANGLE_COMPONENT_TEMPLATE_PARAM)
|
|
- (*num_scopes)++;
|
|
+ dpi->num_saved_scopes++;
|
|
goto recurse_left_right;
|
|
|
|
case DEMANGLE_COMPONENT_QUAL_NAME:
|
|
@@ -4152,42 +4152,42 @@ d_count_templates_scopes (int *num_templates, int *num_scopes,
|
|
case DEMANGLE_COMPONENT_TAGGED_NAME:
|
|
case DEMANGLE_COMPONENT_CLONE:
|
|
recurse_left_right:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- d_left (dc));
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- d_right (dc));
|
|
+ /* PR 89394 - Check for too much recursion. */
|
|
+ if (dpi->recursion > DEMANGLE_RECURSION_LIMIT)
|
|
+ /* FIXME: There ought to be a way to report to the
|
|
+ user that the recursion limit has been reached. */
|
|
+ return;
|
|
+
|
|
+ ++ dpi->recursion;
|
|
+ d_count_templates_scopes (dpi, d_left (dc));
|
|
+ d_count_templates_scopes (dpi, d_right (dc));
|
|
+ -- dpi->recursion;
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_CTOR:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- dc->u.s_ctor.name);
|
|
+ d_count_templates_scopes (dpi, dc->u.s_ctor.name);
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_DTOR:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- dc->u.s_dtor.name);
|
|
+ d_count_templates_scopes (dpi, dc->u.s_dtor.name);
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_EXTENDED_OPERATOR:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- dc->u.s_extended_operator.name);
|
|
+ d_count_templates_scopes (dpi, dc->u.s_extended_operator.name);
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_FIXED_TYPE:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- dc->u.s_fixed.length);
|
|
+ d_count_templates_scopes (dpi, dc->u.s_fixed.length);
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_GLOBAL_CONSTRUCTORS:
|
|
case DEMANGLE_COMPONENT_GLOBAL_DESTRUCTORS:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- d_left (dc));
|
|
+ d_count_templates_scopes (dpi, d_left (dc));
|
|
break;
|
|
|
|
case DEMANGLE_COMPONENT_LAMBDA:
|
|
case DEMANGLE_COMPONENT_DEFAULT_ARG:
|
|
- d_count_templates_scopes (num_templates, num_scopes,
|
|
- dc->u.s_unary_num.sub);
|
|
+ d_count_templates_scopes (dpi, dc->u.s_unary_num.sub);
|
|
break;
|
|
}
|
|
}
|
|
@@ -4222,8 +4222,12 @@ d_print_init (struct d_print_info *dpi, demangle_callbackref callback,
|
|
dpi->next_copy_template = 0;
|
|
dpi->num_copy_templates = 0;
|
|
|
|
- d_count_templates_scopes (&dpi->num_copy_templates,
|
|
- &dpi->num_saved_scopes, dc);
|
|
+ d_count_templates_scopes (dpi, dc);
|
|
+ /* If we did not reach the recursion limit, then reset the
|
|
+ current recursion value back to 0, so that we can print
|
|
+ the templates. */
|
|
+ if (dpi->recursion < DEMANGLE_RECURSION_LIMIT)
|
|
+ dpi->recursion = 0;
|
|
dpi->num_copy_templates *= dpi->num_saved_scopes;
|
|
|
|
dpi->current_template = NULL;
|
|
--
|
|
2.20.1
|
|
|