CVE-2018-9138: Medium severity GNU binutils vulnerability
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demanglenestedargs, demangleargs, doarg, and dotype.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3Fixed in 2.46.90.20260712-1
Event History
Frequently Asked Questions
What is CVE-2018-9138?
CVE-2018-9138 is a vulnerability in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30.
How severe is CVE-2018-9138?
CVE-2018-9138 is a high severity vulnerability.
How does CVE-2018-9138 work?
CVE-2018-9138 allows for stack exhaustion in the C++ demangling functions provided by libiberty, leading to recursive stack frames.
Which software is affected by CVE-2018-9138?
The affected software includes GNU Binutils versions 2.29 and 2.30.
How can I fix CVE-2018-9138?
To fix CVE-2018-9138, update to the recommended versions of binutils and libiberty as provided by the official sources.