Bug 2233969 (CVE-2022-35205)
| Summary: | CVE-2022-35205 binutils: reachable assertion in display_debug_names() in dwarf.c | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | acrosby, ailan, apmukher, bdettelb, caswilli, desktop-qa-list, fjansen, fweimer, gdb-bugs, hkataria, jburrell, jmitchel, jsamir, jsherril, jtanner, kaycoth, keiths, kshier, mcermak, mpolacek, mprchlik, nickc, ohudlick, psegedy, rjones, sipoyare, sthirugn, tsasak, virt-maint, vkrizan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A vulnerability was found in Binutils' readelf, where a reachable assertion failure in the function display_debug_names could be exploited by attackers, leading to a denial-of-service condition.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-11-09 09:16:10 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2233971, 2233972, 2233973, 2234135, 2234136, 2234137, 2234138, 2234139, 2234140, 2234141, 2234142, 2234143, 2234144, 2234145, 2234146, 2234147, 2234148, 2234149 | ||
| Bug Blocks: | 2233947 | ||
|
Description
Guilherme de Almeida Suckevicz
2023-08-23 20:06:19 UTC
Created binutils tracking bugs for this issue: Affects: fedora-all [bug 2233971] Created gdb tracking bugs for this issue: Affects: fedora-all [bug 2233972] Created mingw-binutils tracking bugs for this issue: Affects: fedora-all [bug 2233973] (In reply to Guilherme de Almeida Suckevicz from comment #0) > An issue was discovered in Binutils readelf 2.38.50, reachable assertion > failure in function display_debug_names allows attackers to cause a denial > of service. The SECURITY.txt file found in the upstream GNU Binutils sources makes it clear that bug in inspection tools like readelf are not considered to be security issues, and hence do not qualify for CVE treatment. |