REDHAT-BUG-2122627: Buffer Overflow
Heap/stack buffer overflow in the dlanglname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.
Upstream fix:
https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=5481040197402be6dfee265bd2ff5a4c88e30505
References:
https://gcc.gnu.org/pipermail/gcc-patches/2021-September/579985.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2122627?
The severity of REDHAT-BUG-2122627 is high due to the potential for denial of service through buffer overflow.
How do I fix REDHAT-BUG-2122627?
To fix REDHAT-BUG-2122627, update your libiberty version to incorporate the upstream patch that addresses the buffer overflow.
What types of attacks does REDHAT-BUG-2122627 enable?
REDHAT-BUG-2122627 enables potential denial of service attacks by causing segmentation faults and crashes.
Which software is affected by REDHAT-BUG-2122627?
The affected software for REDHAT-BUG-2122627 is GNU libiberty.
Where can I find more information about REDHAT-BUG-2122627?
You can find more information about REDHAT-BUG-2122627 in its official bug report and relevant patches.