Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-1147
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=7be4186c22f89a87fff048c28910f5d26a0f61ce

Test results:
  binutils-cross-testsuite 2.42 (x86_64-oe-linux):

  Before:
  binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 
unresolved, 20 untested, 99 unsupported

  After:
  binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported (+2 
new passes from nm --ifunc-chars=-- tests)
  gas:      1871 passed, 4 unexpected failures, 2 unsupported
  ld:       1728 passed, 5 unexpected failures, 7 expected failures, 1 
unresolved, 20 untested, 99 unsupported

Signed-off-by: Jaipaul Cheernam <[email protected]>
---
 .../binutils/binutils-2.42.inc                |   1 +
 .../binutils/binutils/CVE-2025-1147.patch     | 110 ++++++++++++++++++
 2 files changed, 111 insertions(+)
 create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch

diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc 
b/meta/recipes-devtools/binutils/binutils-2.42.inc
index d455acd786..063c6cc2a4 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -78,5 +78,6 @@ SRC_URI = "\
      file://CVE-2025-69652.patch \
      file://CVE-2026-6846.patch \
      file://CVE-2025-69645.patch \
+     file://CVE-2025-1147.patch \
 "
 S  = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch 
b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
new file mode 100644
index 0000000000..d8a3f90ede
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
@@ -0,0 +1,110 @@
+From 7be4186c22f89a87fff048c28910f5d26a0f61ce Mon Sep 17 00:00:00 2001
+From: Dmitry Klochkov <[email protected]>
+Date: Tue, 9 Sep 2025 12:06:25 +0200
+Subject: [PATCH] nm: fix treating an ifunc symbol as a stab if
+ '--ifunc-chars=--' is given
+
+If an ifunc symbol is processed in print_symbol(), a 'type' field of a
+'syminfo' structure is set to any character specified by a user with an
+'--ifunc-chars' option.  But afterwards the 'type' field is used to
+check whether a symbol is a stab in print_symbol_info_{bsd,sysv}()
+functions in order to print additional stab related data.  If the 'type'
+field equals '-', a symbol is treated as a stab.  If '--ifunc-chars=--'
+is given, all ifunc symbols will be treated as stab symbols and
+uninitialized stab related fields of the 'syminfo' structure will be
+printed which can lead to segmentation fault.
+
+To fix this, check if a symbol is a stab before override the 'type'
+field.  Also, add a test case for this fix.
+
+       PR binutils/32556
+       * nm.c (extended_symbol_info): Add is_stab.
+       (print_symbol): Check if a symbol is a stab.
+       (print_symbol_info_bsd): Use info->is_stab.
+       (print_symbol_info_sysv): Use info->is_stab.
+       * testsuite/binutils-all/nm.exp: Test nm --ifunc-chars=--.
+
+Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=32556
+Fixes: e6f6aa8d184 ("Add option to nm to change the characters displayed for 
ifunc symbols")
+Signed-off-by: Dmitry Klochkov <[email protected]>
+---
+ binutils/nm.c                          | 10 +++++++---
+ binutils/testsuite/binutils-all/nm.exp | 17 +++++++++++++++++
+ 2 files changed, 24 insertions(+), 3 deletions(-)
+
+Upstream-Status: Backport 
[https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce]
+CVE: CVE-2025-1147
+
+Signed-off-by: Jaipaul Cheernam <[email protected]>
+
+diff --git a/binutils/nm.c b/binutils/nm.c
+index dce9207f44f..c3d118a93c3 100644
+--- a/binutils/nm.c
++++ b/binutils/nm.c
+@@ -70,6 +70,7 @@ struct extended_symbol_info
+   bfd_vma ssize;
+   elf_symbol_type *elfinfo;
+   coff_symbol_type *coffinfo;
++  bool is_stab;
+   /* FIXME: We should add more fields for Type, Line, Section.  */
+ };
+ #define SYM_VALUE(sym)       (sym->sinfo->value)
+@@ -1208,8 +1209,11 @@ print_symbol (bfd *        abfd,
+ 
+   bfd_get_symbol_info (abfd, sym, &syminfo);
+ 
++  info.is_stab = false;
++  if (syminfo.type == '-')
++    info.is_stab = true;
+   /* PR 22967 - Distinguish between local and global ifunc symbols.  */
+-  if (syminfo.type == 'i'
++  else if (syminfo.type == 'i'
+       && sym->flags & BSF_GNU_INDIRECT_FUNCTION)
+     {
+       if (ifunc_type_chars == NULL || ifunc_type_chars[0] == 0)
+@@ -1873,7 +1877,7 @@ print_symbol_info_bsd (struct extended_symbol_info 
*info, bfd *abfd)
+ 
+   printf (" %c", SYM_TYPE (info));
+ 
+-  if (SYM_TYPE (info) == '-')
++  if (info->is_stab)
+     {
+       /* A stab.  */
+       printf (" ");
+@@ -1902,7 +1906,7 @@ print_symbol_info_sysv (struct extended_symbol_info 
*info, bfd *abfd)
+ 
+   printf ("|   %c  |", SYM_TYPE (info));
+ 
+-  if (SYM_TYPE (info) == '-')
++  if (info->is_stab)
+     {
+       /* A stab.  */
+       printf ("%18s|  ", SYM_STAB_NAME (info));               /* (C) Type.  */
+diff --git a/binutils/testsuite/binutils-all/nm.exp 
b/binutils/testsuite/binutils-all/nm.exp
+index fea68bf76bc..1feb8578fba 100644
+--- a/binutils/testsuite/binutils-all/nm.exp
++++ b/binutils/testsuite/binutils-all/nm.exp
+@@ -329,6 +329,23 @@ if [is_elf_format] {
+           fail "$testname (local ifunc)"
+       }
+ 
++      # PR 32556
++      # Test nm --ifunc-chars=--
++
++      set got [binutils_run $NM "$NMFLAGS --ifunc-chars=-- $tmpfile"]
++
++      if [regexp -line "^\\S+ - global_foo$" $got] then {
++          pass "$testname=-- (global ifunc)"
++      } else {
++          fail "$testname=-- (global ifunc)"
++      }
++
++      if [regexp -line "^\\S+ - local_foo$" $got] then {
++          pass "$testname=-- (local ifunc)"
++      } else {
++          fail "$testname=-- (local ifunc)"
++      }
++
+       if { $verbose < 1 } {
+           remote_file host delete "tmpdir/ifunc.o"
+       }
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243248): 
https://lists.openembedded.org/g/openembedded-core/message/243248
Mute This Topic: https://lists.openembedded.org/mt/120714612/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to