REDHAT-BUG-1956423: Low severity GNU binutils vulnerability
A flaw was discovered in GNU libiberty within demanglepath() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Reference: https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1925348
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU Binutilsto a version that resolves this vulnerability.Fixed in 2.36
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1956423?
The severity of REDHAT-BUG-1956423 is considered high due to the potential for crashing applications.
How do I fix REDHAT-BUG-1956423?
To fix REDHAT-BUG-1956423, update to a patched version of GNU Binutils beyond 2.36.
What versions are affected by REDHAT-BUG-1956423?
REDHAT-BUG-1956423 affects GNU Binutils version 2.36.
What component does REDHAT-BUG-1956423 affect?
REDHAT-BUG-1956423 affects the demangle_path() function in rust-demangle.c.
What type of vulnerability is REDHAT-BUG-1956423?
REDHAT-BUG-1956423 is a stack exhaustion vulnerability that can lead to application crashes.