REDHAT-BUG-2460012: Medium severity GNU readelf (Binutils) vulnerability
Two DoS vulnerabilities in readelf 2.46: 1. Resource exhaustion: 1KB crafted ELF triggers 6.3TB allocation (357M relocation entries), OOM kill 2. Null pointer deref: malformed shentsize/shoff causes SIGSEGV
Found via AFL++ QEMU-mode fuzzing. PoC files provided. Not disclosed publicly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460012?
REDHAT-BUG-2460012 is classified as a high severity vulnerability due to its potential for causing denial-of-service (DoS) conditions.
How do I fix REDHAT-BUG-2460012?
To mitigate REDHAT-BUG-2460012, consider upgrading to a version of GNU readelf (Binutils) that addresses these vulnerabilities.
What are the specific vulnerabilities identified in REDHAT-BUG-2460012?
REDHAT-BUG-2460012 includes two vulnerabilities: resource exhaustion leading to out-of-memory conditions and a null pointer dereference causing a segmentation fault.
Is REDHAT-BUG-2460012 publicly disclosed?
No, REDHAT-BUG-2460012 has not been publicly disclosed, but proof-of-concept files have been provided.
Which version of readelf is affected by REDHAT-BUG-2460012?
The affected version of readelf related to REDHAT-BUG-2460012 is specifically version 2.46.