[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Bug binutils/28420] New: segv in objdump at disassemble_bytes objdump.c
From: |
irfanariq at kaist dot ac.kr |
Subject: |
[Bug binutils/28420] New: segv in objdump at disassemble_bytes objdump.c:3059 |
Date: |
Tue, 05 Oct 2021 17:38:52 +0000 |
https://sourceware.org/bugzilla/show_bug.cgi?id=28420
Bug ID: 28420
Summary: segv in objdump at disassemble_bytes objdump.c:3059
Product: binutils
Version: unspecified
Status: UNCONFIRMED
Severity: normal
Priority: P2
Component: binutils
Assignee: unassigned at sourceware dot org
Reporter: irfanariq at kaist dot ac.kr
Target Milestone: ---
Created attachment 13703
--> https://sourceware.org/bugzilla/attachment.cgi?id=13703&action=edit
poc and full stack trace
Hello,
We are currently working on fuzz testing feature, and we found a **SEGV** on
`objdump`.
The stack traces are as follow:
```st
==2673==ERROR: AddressSanitizer: SEGV on unknown address 0x0000071a5d68 (pc
0x55ca946b0f38 bp 0x7ffd51b38d50 sp 0x7ffd51b38b00 T0)
==2673==The signal is caused by a READ memory access.
#0 0x55ca946b0f37 in disassemble_bytes objdump.c:3059
#1 0x55ca946b3342 in disassemble_section objdump.c:3455
#2 0x55ca94b7e3c0 in bfd_map_over_sections
.../binutils-git/bfd/section.c:1383
#3 0x55ca946b4293 in disassemble_data objdump.c:3599
#4 0x55ca946bb6cc in dump_bfd objdump.c:5006
#5 0x55ca946bb994 in display_object_bfd objdump.c:5068
#6 0x55ca946bbd2f in display_any_bfd objdump.c:5158
#7 0x55ca946bbda6 in display_file objdump.c:5179
#8 0x55ca946bd15a in main objdump.c:5529
```
The full stack trace is attached.
**Step to reproduce**
We configured `objdump` using `CFLAGS="-g -O0 -fsanitize=address" ./configure
--prefix=$(pwd)/ --disable-shared --enable-targets=all` and build it using
`make -j 10`, and run it with:
```
./objdump --reloc -a -r 32 ld -Ttext <attached file> -d
```
The input file is attached.
**Environment**
- OS: Ubuntu 18.04.5 LTS
- GCC version: gcc 7.5.0
- binutils version: commit (98ca73a) of master branch on sourceware git
([link](https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=98ca73afe51e1e921915c37f242c88d4d445841c))
Thank you.
--
You are receiving this mail because:
You are on the CC list for the bug.
- [Bug binutils/28420] New: segv in objdump at disassemble_bytes objdump.c:3059,
irfanariq at kaist dot ac.kr <=
- [Bug binutils/28420] segv in objdump at disassemble_bytes objdump.c:3059, amodra at gmail dot com, 2021/10/06
- [Bug binutils/28420] segv in objdump at disassemble_bytes objdump.c:3059, cvs-commit at gcc dot gnu.org, 2021/10/06
- [Bug binutils/28420] segv in objdump at disassemble_bytes objdump.c:3059, amodra at gmail dot com, 2021/10/06
- [Bug binutils/28420] segv in objdump at disassemble_bytes objdump.c:3059, amodra at gmail dot com, 2021/10/06
- [Bug binutils/28420] segv in objdump at disassemble_bytes objdump.c:3059, amodra at gmail dot com, 2021/10/07
- [Bug binutils/28420] segv in objdump at disassemble_bytes objdump.c:3059, cvs-commit at gcc dot gnu.org, 2021/10/30