CVE-2022-44840: Buffer Overflow
Published Aug 22, 2023
·Updated
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function findsectioninset in file readelf.c.
Affected Software
2 affected componentsFixes available
GNU binutils<2.40
debian/binutils<=2.35.2-2
2.40-22.44-3
Remediation
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:12 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·03:40 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·05:08 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this heap buffer overflow vulnerability?
The vulnerability ID for this heap buffer overflow vulnerability is CVE-2022-44840.
2
What software is affected by this vulnerability?
The GNU Binutils package before version 2.40 and certain versions of the binutils package in Debian and Ubuntu are affected by this vulnerability.
3
What is the severity of CVE-2022-44840?
The severity of CVE-2022-44840 is high with a CVSS score of 7.8.
4
How can I fix this vulnerability in GNU Binutils?
To fix this vulnerability in GNU Binutils, you need to update to version 2.40 or later.
5
How can I fix this vulnerability in Debian and Ubuntu?
To fix this vulnerability in Debian, update the binutils package to version 2.40-2 or 2.41-5. For Ubuntu, update the binutils package to the respective versions specified in the Ubuntu security advisories.