CVE-2018-20623: Use After Free
In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the processarchive function in readelf.c via a crafted ELF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-20623?
CVE-2018-20623 is a vulnerability in GNU Binutils 2.31.1 that allows a use-after-free exploit when processing a crafted ELF file.
How does CVE-2018-20623 affect GNU Binutils?
CVE-2018-20623 affects GNU Binutils 2.31.1 by causing a use-after-free issue in the elfcomm.c error function when called from the process_archive function in readelf.c.
How can I fix CVE-2018-20623 on Ubuntu Xenial?
On Ubuntu Xenial, you can fix CVE-2018-20623 by upgrading to binutils version 2.26.1-1ubuntu1~16.04.8 or higher.
How can I fix CVE-2018-20623 on Ubuntu Bionic?
On Ubuntu Bionic, you can fix CVE-2018-20623 by upgrading to binutils version 2.30-21ubuntu1~18.04.3 or higher.
How can I fix CVE-2018-20623 on Debian?
On Debian, you can fix CVE-2018-20623 by upgrading to binutils version 2.35.2-2, 2.40-2, or 2.41-5 or higher.