REDHAT-BUG-1646477: Low severity elfutils vulnerability
A flaw was found in elfutils through v0.174. An Invalid Memory Address Dereference exists in the function elfend in libelf. Although eu-size is intended to support ar files inside ar files, handlear in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file.
References: https://sourceware.org/bugzilla/showbug.cgi?id=23787 https://sourceware.org/ml/elfutils-devel/2018-q4/msg00057.html
Upstream Patch: https://sourceware.org/git/?p=elfutils.git;a=commit;h=22d2d082d57a7470fadc0eae67179553f4919209
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1646477?
The severity of REDHAT-BUG-1646477 is categorized as critical due to its potential for causing invalid memory access.
How do I fix REDHAT-BUG-1646477?
To fix REDHAT-BUG-1646477, upgrade elfutils to the latest version beyond 0.174 that contains the patch addressing this vulnerability.
What impact does REDHAT-BUG-1646477 have on systems?
The impact of REDHAT-BUG-1646477 may include application crashes, memory corruption, or execution of arbitrary code if exploited.
Which versions of elfutils are affected by REDHAT-BUG-1646477?
Versions of elfutils up to and including 0.174 are affected by REDHAT-BUG-1646477.
Is there a workaround for REDHAT-BUG-1646477?
There is no official workaround for REDHAT-BUG-1646477; the best course of action is to apply the appropriate update.