libctf: allow ctf_arc_bufpreamble to fail

The recent libctf fix for ctf_arc_bufpreamble missed a case:
what if the input is exactly sizeof (ctf_archive_t) in size (which can
happen if the archive has no members at all, so returning the preamble
from one of the members is in any case impossible?).  In this case
it'll return an off-the-end pointer, and its caller will overrun.

Allow it to fail in this case, returning NULL, and adjust its sole
caller.  The caller's conclusions in this case will be wrong (it will
conclude that the archive is connected to .symtab), but the incorrect
conclusions are harmless because the lack of archive members will
immediately cause a failure in ctf_arc_bufopen(), and an error return.

Thanks to Alan Modra for the original fix this soups up.

libctf/
	* ctf-archive.c (ctf_arc_bufpreamble): Fail if the archive is
	too short (or empty, with no dicts to contain preambles),
	returning NULL.
	* ctf-open-bfd.c (ctf_bfdopen_ctfsect): Handle a NULL return.
This commit is contained in:
Nick Alcock
2025-11-03 17:15:32 +00:00
parent 7c8311eca7
commit 0970b8c458
2 changed files with 11 additions and 6 deletions

View File

@@ -389,14 +389,19 @@ ctf_arc_symsect_endianness (ctf_archive_t *arc, int little_endian)
/* Get the CTF preamble from data in a buffer, which may be either an archive or
a CTF dict. If multiple dicts are present in an archive, the preamble comes
from an arbitrary dict. The preamble is a pointer into the ctfsect passed
in. */
in. Returns NULL if this cannot be a CTF archive or dict at all. */
const ctf_preamble_t *
ctf_arc_bufpreamble (const ctf_sect_t *ctfsect)
{
if (ctfsect->cts_data != NULL
&& ctfsect->cts_size >= sizeof (struct ctf_archive)
&& (le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC))
if (ctfsect->cts_data == NULL
|| ctfsect->cts_size < sizeof (uint64_t)
|| (le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC
&& ctfsect->cts_size < (sizeof (ctf_archive_t) + sizeof (uint64_t))))
return NULL;
if (ctfsect->cts_size >= (sizeof (struct ctf_archive) + sizeof (uint64_t))
&& le64toh ((*(uint64_t *) ctfsect->cts_data)) == CTFA_MAGIC)
{
struct ctf_archive *arc = (struct ctf_archive *) ctfsect->cts_data;
return (const ctf_preamble_t *) ((char *) arc + le64toh (arc->ctfa_ctfs)

View File

@@ -120,13 +120,13 @@ ctf_bfdopen_ctfsect (struct bfd *abfd _libctf_unused_,
}
preamble = ctf_arc_bufpreamble (ctfsect);
if (preamble->ctp_flags & CTF_F_DYNSTR)
if (preamble && (preamble->ctp_flags & CTF_F_DYNSTR))
{
symhdr = &elf_tdata (abfd)->dynsymtab_hdr;
strtab_name = ".dynstr";
symtab_name = ".dynsym";
}
else
else /* Might not be CTF at all: ctf_arc_bufopen will fail if so. */
{
symhdr = &elf_tdata (abfd)->symtab_hdr;
strtab_name = ".strtab";