REDHAT-BUG-1960717: Low severity GNU binutils vulnerability
A flaw was discovered in objdump as distributed in GNU Binutils version 2.36. A large section parameter can be passed to avrelf32loadrecordsfromsection() leading to DoS and memory corruption.
Reference: https://sourceware.org/bugzilla/showbug.cgi?id=27294
Upstream patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=1cfcf3004e1830f8fe9112cfcd15285508d2c2b7
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU Binutils (objdump)to a version that resolves this vulnerability.Fixed in 2.36Patch 27294
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1960717?
The severity of REDHAT-BUG-1960717 is categorized as a DoS and memory corruption vulnerability.
How do I fix REDHAT-BUG-1960717?
To fix REDHAT-BUG-1960717, update your GNU Binutils to a patched version that addresses this flaw.
Which versions of GNU Binutils are affected by REDHAT-BUG-1960717?
REDHAT-BUG-1960717 affects GNU Binutils version 2.36 and potentially earlier versions.
What can be the impact of exploiting REDHAT-BUG-1960717?
Exploiting REDHAT-BUG-1960717 can lead to denial of service and memory corruption.
What component of GNU Binutils does REDHAT-BUG-1960717 affect?
REDHAT-BUG-1960717 affects the objdump component of GNU Binutils.