[Bug 1763094] Re: Multiple memory corruption in ld-new (binuitils-2.30-15ubuntu1)
Launchpad Bug Tracker
1763094 at bugs.launchpad.net
Thu Jun 7 06:25:27 UTC 2018
This bug was fixed in the package binutils - 2.30-20ubuntu2~18.04
---------------
binutils (2.30-20ubuntu2~18.04) bionic-security; urgency=medium
* Combined security update / SRU: LP: #1771635, LP: #1769657.
binutils (2.30-20ubuntu2) cosmic; urgency=medium
* Fix PR gprof/23056, memory corruption in gprof. LP: #1763098.
* Fix PR binutils/23054, memory corruption in as. LP: #1763096.
* Fix PR ld/23055, memory corruption in ld. LP: #1763094.
binutils (2.30-20ubuntu1) cosmic; urgency=medium
* Merge with Debian; remaining changes:
- Build from upstream sources.
binutils (2.30-20) unstable; urgency=medium
* Update, taken from the 2.30 branch 20180516.
- Fix PR binutils/23109, disassembly mask for vector sdot on AArch64.
- Fix uninitialised memory acccess in COFF bfd backend.
- Update Portuguese translations.
binutils (2.30-19) unstable; urgency=medium
* Build-depend on procps.
binutils (2.30-17ubuntu1) cosmic; urgency=medium
* Merge with Debian; remaining changes:
- Build from upstream sources.
binutils (2.30-17) unstable; urgency=medium
* Update, taken from the 2.30 branch 20180502.
- Fix PR ld/23123, PR ld/22374, PowerPC32 ifunc regression.
- AArch64: Fix the mask for the sqrdml(a|s)h instructions.
* Fix unintialized memory in aarch64 opcodes, taken from the trunk.
binutils (2.30-16) unstable; urgency=medium
* Update, taken from the 2.30 branch 20180425.
- Fix PR ld 22782, x86: Remove the unused _GLOBAL_OFFSET_TABLE_.
- Update spanish and russian translations.
* Add amd64, i386, x32 and riscv64 cross compilers as build (test)
dependencies.
-- Matthias Klose <doko at ubuntu.com> Wed, 16 May 2018 15:20:51 -0400
** Changed in: binutils (Ubuntu Bionic)
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to binutils in Ubuntu.
https://bugs.launchpad.net/bugs/1763094
Title:
Multiple memory corruption in ld-new (binuitils-2.30-15ubuntu1)
Status in binutils package in Ubuntu:
Fix Released
Status in binutils source package in Bionic:
Fix Released
Bug description:
Dear all,
The following binutils ld-new memory corruptions were found by a modified version of the kAFL fuzzer (https://github.com/RUB-SysSec/kAFL). I have attached the crashing inputs and each ASAN report.
Steps to reproduce:
Build current verison of binutils:
```
pull-lp-source binutils
cd binutils-2.30
CC=clang CXX=clang++ CFLAGS="-fsanitize=address -fsanitize-recover=address -ggdb" CXXFLAGS="-fsanitize=address -fsanitize-recover=address -ggdb" LDFLAGS="-fsanitize=address" ./configure
CC=clang CXX=clang++ CFLAGS="-fsanitize=address -fsanitize-recover=address -ggdb" CXXFLAGS="-fsanitize=address
-fsanitize-recover=address -ggdb" LDFLAGS="-fsanitize=address" make
```
Run inputs under ASAN:
```
ASAN_OPTIONS=halt_on_error=false:allow_addr2line=true ./ld-new $file
```
We can verify those issues for ld-new binuitils-2.30-15ubuntu1 (Ubuntu
16.04.4 LTS / sources from "pull-lp-source bintuils").
Credits: Sergej Schumilo, Cornelius Aschermann (both of Ruhr-
Universität Bochum)
Best regards,
Sergej Schumilo
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763094/+subscriptions
More information about the foundations-bugs
mailing list