CVE-2017-7226: Critical severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
The peILFobjectp function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to information disclosure as well.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade
GNU Binutils (libbfd / Binary File Descriptor library) pe_ILF_object_pto a version that resolves this vulnerability.Fixed in 2.28
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-7226.
What is the affected software?
The affected software includes GNU Binutils version 2.28.
What is the severity of CVE-2017-7226?
The severity of CVE-2017-7226 is not specified in the information provided.
How does CVE-2017-7226 work?
CVE-2017-7226 is a heap-based buffer over-read vulnerability in the pe_ILF_object_p function of the libbfd library.
How can I fix CVE-2017-7226?
To fix CVE-2017-7226, you should update your GNU Binutils to a version that is not affected, such as 2.26.1-1ubuntu1~16.04.8+.