CVE-2021-3530: High severity GNU binutils vulnerability
A flaw was discovered in GNU libiberty within demanglepath() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU Binutils (libiberty)to a version that resolves this vulnerability.Fixed in 2.36
Event History
Frequently Asked Questions
What is CVE-2021-3530?
CVE-2021-3530 is a vulnerability found in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36.
What is the severity of CVE-2021-3530?
The severity of CVE-2021-3530 is high with a CVSS score of 7.5.
How does CVE-2021-3530 affect GNU Binutils?
CVE-2021-3530 affects GNU Binutils version 2.36.
How does CVE-2021-3530 affect NetApp ONTAP Select Deploy administration utility?
CVE-2021-3530 does not affect NetApp ONTAP Select Deploy administration utility.
How can I fix CVE-2021-3530?
To fix CVE-2021-3530, users should update to a version of GNU Binutils where the vulnerability is patched.