CVE-2018-18484: Medium severity GNU binutils vulnerability
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplusdemangletype, dbarefunctiontype, dfunctiontype.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3Fixed in 2.46.90.20260712-1
Event History
Frequently Asked Questions
What is CVE-2018-18484?
CVE-2018-18484 is a vulnerability in GNU libiberty, as distributed in GNU Binutils 2.31, that causes stack exhaustion in the C++ demangling functions.
How does CVE-2018-18484 affect me?
If you are using GNU libiberty, as distributed in GNU Binutils 2.31, your system is vulnerable to stack exhaustion.
How can I fix CVE-2018-18484?
To fix CVE-2018-18484, you should update your Binutils package to version 2.35.2-2 or higher.
Are there any workarounds for CVE-2018-18484?
There are no known workarounds for CVE-2018-18484.
Where can I find more information about CVE-2018-18484?
You can find more information about CVE-2018-18484 at the following references: [link1], [link2], [link3].