CVE-2022-38533: Medium severity binutils vulnerability
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfdgetl32 when called from the stripmain function in strip-new via a crafted file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability identified by CVE-2022-38533?
The vulnerability identified by CVE-2022-38533 is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
Which software is affected by CVE-2022-38533?
The GNU Binutils before version 2.40 and Fedora versions 36 and 37 are affected by CVE-2022-38533.
What is the severity of CVE-2022-38533?
CVE-2022-38533 has a severity score of 5.5 (medium).
How can I fix the vulnerability CVE-2022-38533?
To fix the vulnerability CVE-2022-38533, update your GNU Binutils installation to version 2.40 or higher and update Fedora to a version higher than 37.
Where can I find more information about CVE-2022-38533?
You can find more information about CVE-2022-38533 in the provided references: [GitHub commit](https://github.com/bminor/binutils-gdb/commit/45d92439aebd0386ef8af76e1796d08cfe457e1d) and [Fedora mailing list](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/).