Bug 2167498 (CVE-2023-25585)
| Summary: | CVE-2023-25585 binutils: Field `file_table` of `struct module *module` is uninitialized | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | acrosby, ailan, bdettelb, caswilli, dffrench, dfreiber, dkuc, doconnor, drow, fjansen, fweimer, gdb-bugs, gzaronik, hbraun, hkataria, jburrell, jforrest, jkoehler, jmitchel, jsamir, jtanner, jwon, kaycoth, keiths, kholdawa, kshier, lcouzens, lphiri, mcermak, micjohns, mnewsome, mpolacek, mprchlik, mskarbek, ngough, nickc, ohudlick, rgodfrey, rjones, sipoyare, sthirugn, teagle, virt-maint, vkrizan, vkumar |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: |
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-03-01 17:58:42 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2174126, 2174127, 2174128, 2174129, 2174130, 2174131, 2174132, 2174133, 2174134, 2174182, 2174183 | ||
| Bug Blocks: | 2160830 | ||
|
Description
Pedro Sampaio
2023-02-06 19:57:24 UTC
Another vms-alpha specific fix. Only affects binutils in RHEL 8/7/6. See BZ 2167467 for more details on why bugs in the vms-alpha alpha support is restricted to these releases. This does not affect gdb in RHEL or Fedora; gdb does not have or build the affected code. While bfd/vms-alpha.c is included in the gdb srpm, gdb.spec only enables targets that are supported by RHEL (ppc64/ppc64le, aarch64, s390x, x86_64). This file is therefore never built in gdb. |