REDHAT-BUG-1574696: Low severity GNU binutils vulnerability
A flaw was found in the bfdXXbfdcopyprivatebfddatacommon function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (externalIMAGEDEBUGDIRECTORY) edd so that the address exceeds its own memory region, resulting in an out-of-bounds memory write, as demonstrated by objcopy copying private info with bfdpex64bfdcopyprivatebfddatacommon in pex64igen.c.
References: https://sourceware.org/bugzilla/showbug.cgi?id=23110
Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aa4a8c2a2a67545e90c877162c53cc9de42dc8b4
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1574696?
The severity of REDHAT-BUG-1574696 is classified as a medium-level vulnerability due to potential unbounded loops.
How do I fix REDHAT-BUG-1574696?
To fix REDHAT-BUG-1574696, you should update to the latest version of GNU Binutils or apply the relevant patches provided by your Linux distribution.
What software is affected by REDHAT-BUG-1574696?
REDHAT-BUG-1574696 affects the Binary File Descriptor (BFD) library as distributed in GNU Binutils 2.30.
What is the impact of REDHAT-BUG-1574696?
The impact of REDHAT-BUG-1574696 is that it may cause denial of service through the potential for an unbounded loop when processing specific inputs.
Is there a workaround for REDHAT-BUG-1574696?
Currently, the best workaround for REDHAT-BUG-1574696 is to avoid using affected versions of GNU Binutils until a fix is applied.