From 3515e4484577c68b339093bfff6fb5d96dccd3c5 Mon Sep 17 00:00:00 2001 From: Marco Casaroli Date: Fri, 9 Oct 2026 01:14:02 +0200 Subject: [PATCH] libs/libc/machine/arm64: Do not dereference a NULL symbol in up_relocateadd(). libelf_relocateadd() passes sym as NULL for a relocation against symbol index 0, such as R_AARCH64_NONE. up_relocateadd() read sym->st_value first, so loading a module with such a relocation faulted in the kernel. Accept a NULL symbol for R_AARCH64_NONE and fail any other type, as the other architectures do. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Marco Casaroli --- libs/libc/machine/arm64/arch_elf.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/libs/libc/machine/arm64/arch_elf.c b/libs/libc/machine/arm64/arch_elf.c index cf23f35bf33..210409a64fa 100644 --- a/libs/libc/machine/arm64/arch_elf.c +++ b/libs/libc/machine/arm64/arch_elf.c @@ -485,11 +485,20 @@ int up_relocateadd(const Elf64_Rela *rel, const Elf64_Sym *sym, uint64_t val; int ret = 0; + /* Only R_AARCH64_NONE may come without a symbol (symbol index 0) */ + + if (sym == NULL && ELF64_R_TYPE(rel->r_info) != R_AARCH64_NONE) + { + berr("ERROR: Relocation type %d has no symbol\n", + (int)ELF64_R_TYPE(rel->r_info)); + return -EINVAL; + } + /* addr corresponds to P in the AArch64 ELF document. */ /* val corresponds to (S + A) in the AArch64 ELF document. */ - val = sym->st_value + rel->r_addend; + val = (sym != NULL ? sym->st_value : 0) + rel->r_addend; /* Handle the relocation by relocation type */