diff options
author | James Clarke <jrtc27@jrtc27.com> | 2017-01-03 16:15:15 +0000 |
---|---|---|
committer | Alan Modra <amodra@gmail.com> | 2017-01-04 08:53:43 +1030 |
commit | ae4fda663812129df67e3a70691787060242c0f9 (patch) | |
tree | 7f1b2ec83550b9c79e1b50da727b8204ddeb6593 /bfd/elf64-alpha.c | |
parent | cc917fd93d2a836adfd61b91df021cf835e88fd1 (diff) | |
download | binutils-gdb-ae4fda663812129df67e3a70691787060242c0f9.tar.gz |
bfd: alpha: Fix crash caused by double free with --no-keep-memory
Without this, ld has been seen to crash in libc when freeing tsec_free:
*** Error in `/usr/bin/ld': double free or corruption (!prev): 0x0000000120ceb6a0 ***
_bfd_elf_link_read_relocs will always return the cached value if
present, even if keep_memory is false, therefore setting tsec_free to
NULL only when keep_memory is true is not sufficient.
* elf64-alpha.c (elf64_alpha_relax_opt_call): Don't set tsec_free
if relocs are cached.
Diffstat (limited to 'bfd/elf64-alpha.c')
-rw-r--r-- | bfd/elf64-alpha.c | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/bfd/elf64-alpha.c b/bfd/elf64-alpha.c index 4fa47437668..b4a50f4e777 100644 --- a/bfd/elf64-alpha.c +++ b/bfd/elf64-alpha.c @@ -3215,7 +3215,9 @@ elf64_alpha_relax_opt_call (struct alpha_relax_info *info, bfd_vma symval) if (tsec_relocs == NULL) return 0; tsec_relend = tsec_relocs + info->tsec->reloc_count; - tsec_free = (info->link_info->keep_memory ? NULL : tsec_relocs); + tsec_free = (elf_section_data (info->tsec)->relocs == tsec_relocs + ? NULL + : tsec_relocs); } /* Recover the symbol's offset within the section. */ |