Go to file
Pedro Alves f0ae6fc35c PR gdb/15236: gdbserver write to linux memory with zero length corrupts stack
PROBLEM:

The function linux_write_memory () in linux-low.c allocates a buffer
on the stack to hold a copy of the data to be written.

  register PTRACE_XFER_TYPE *buffer = (PTRACE_XFER_TYPE *)
    alloca (count * sizeof (PTRACE_XFER_TYPE));

"count" is the number of bytes to be written, rounded up to the
nearest multiple of sizeof (PTRACE_XFER_TYPE) and allowing for not
being an aligned address. The function later uses

  buffer[0] = ptrace (PTRACE_PEEKTEXT, pid,
                      (PTRACE_ARG3_TYPE) (uintptr_t) addr, 0);

The problem is that this function can be called to write zero bytes on
an aligned address, for example when receiving an X packet of length 0
(used to test if 8-bit write is supported). Under these circumstances,
count can be zero.

Since in this case, buffer[0] may never have been allocated, the stack
is corrupted and gdbserver may crash.

SOLUTION:

Writing zero bytes should always succeed. The patch below returns
successfully early if the length is zero, so avoiding the stack
corruption.

Verified on the ARC GDB 7.5.1 port.

2013-03-07  Jeremy Bennett  <jeremy.bennett@embecosm.com>

	PR server/15236

	* linux-low.c (linux_write_memory): Return early success if LEN is
	zero.
2013-03-07 09:47:57 +00:00
bfd daily update 2013-03-06 23:00:05 +00:00
binutils * strings.c (get_char): Dispense with buf[]. Instead shift 2013-03-06 13:40:51 +00:00
config * configure: Regenerate after syncing config/. 2013-02-04 23:31:16 +00:00
cpu
elfcpp elfcpp/ 2013-03-01 22:45:56 +00:00
etc
gas Add to the AArch64 GAS the missing support for hexadecimal-format 2013-03-05 16:31:44 +00:00
gdb PR gdb/15236: gdbserver write to linux memory with zero length corrupts stack 2013-03-07 09:47:57 +00:00
gold * testsuite/discard_locals_relocatable_test.c: Add a powerpc 2013-03-07 05:33:50 +00:00
gprof Rotate binutils ChangeLog for 2013 2013-01-02 17:06:32 +00:00
include Restore patch lost in last merge from GCC. 2013-03-01 23:40:38 +00:00
intl
ld * ldfile.c (ldfile_open_command_file_1): Return after einfo 2013-03-06 13:48:46 +00:00
libdecnumber merge from gcc 2013-02-07 04:43:49 +00:00
libiberty merge from gcc 2013-03-01 23:00:28 +00:00
opcodes Add RegRex64 to riz 2013-03-02 01:57:48 +00:00
readline
sim * simops.c (v850_rotl): New function. 2013-01-28 10:06:51 +00:00
texinfo
.cvsignore
.gitignore Sync the root .gitignore file with GCC's. 2013-01-11 15:17:35 +00:00
ChangeLog * configure.ac: Sync with GCC repo. 2013-02-15 17:55:25 +00:00
compile
config-ml.in
config.guess * config.guss: Update from config repo. 2013-01-08 22:42:34 +00:00
config.rpath
config.sub * config.sub: Update from config repo. 2013-01-11 12:57:41 +00:00
configure * configure.ac: Sync with GCC repo. 2013-02-15 17:55:25 +00:00
configure.ac * configure.ac: Sync with GCC repo. 2013-02-15 17:55:25 +00:00
COPYING
COPYING3
COPYING3.LIB
COPYING.LIB
COPYING.LIBGLOSS 2013-01-07 Jeff Johnston <jjohnstn@redhat.com> 2013-01-07 21:39:26 +00:00
COPYING.NEWLIB
depcomp
djunpack.bat
install-sh
libtool.m4
lt~obsolete.m4
ltgcc.m4
ltmain.sh
ltoptions.m4
ltsugar.m4
ltversion.m4
MAINTAINERS
Makefile.def * configure.ac: Sync with GCC repo. 2013-01-15 21:47:02 +00:00
Makefile.in * configure.ac: Sync with GCC repo. 2013-01-15 21:47:02 +00:00
Makefile.tpl * Makefile.tpl (BOOT_ADAFLAGS): Remove -gnata. 2013-01-11 11:48:54 +00:00
makefile.vms
missing
mkdep
mkinstalldirs
move-if-change
README
README-maintainer-mode
setup.com
src-release
symlink-tree
ylwrap

		   README for GNU development tools

This directory contains various GNU compilers, assemblers, linkers, 
debuggers, etc., plus their support routines, definitions, and documentation.

If you are receiving this as part of a GDB release, see the file gdb/README.
If with a binutils release, see binutils/README;  if with a libg++ release,
see libg++/README, etc.  That'll give you info about this
package -- supported targets, how to use it, how to report bugs, etc.

It is now possible to automatically configure and build a variety of
tools with one command.  To build all of the tools contained herein,
run the ``configure'' script here, e.g.:

	./configure 
	make

To install them (by default in /usr/local/bin, /usr/local/lib, etc),
then do:
	make install

(If the configure script can't determine your type of computer, give it
the name as an argument, for instance ``./configure sun4''.  You can
use the script ``config.sub'' to test whether a name is recognized; if
it is, config.sub translates it to a triplet specifying CPU, vendor,
and OS.)

If you have more than one compiler on your system, it is often best to
explicitly set CC in the environment before running configure, and to
also set CC when running make.  For example (assuming sh/bash/ksh):

	CC=gcc ./configure
	make

A similar example using csh:

	setenv CC gcc
	./configure
	make

Much of the code and documentation enclosed is copyright by
the Free Software Foundation, Inc.  See the file COPYING or
COPYING.LIB in the various directories, for a description of the
GNU General Public License terms under which you can copy the files.

REPORTING BUGS: Again, see gdb/README, binutils/README, etc., for info
on where and how to report problems.