Bug 2334774
Summary: | CVE-2024-56737 radare2: heap-based buffer overflow [epel-8] | ||
---|---|---|---|
Product: | [Fedora] Fedora EPEL | Reporter: | Avinash Hanwate <ahanwate> |
Component: | radare2 | Assignee: | Michal Ambroz <rebus> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | epel8 | CC: | rebus |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | {"flaws": ["64ed7d1a-0f0d-430d-a0cf-20d9d6e7e93c"]} | ||
Fixed In Version: | radare2-5.9.8-7.fc42 radare2-5.9.8-7.fc41 radare2-5.9.8-7.fc40 radare2-5.9.8-7.el10_1 radare2-5.9.8-7.el9 radare2-5.9.8-8.el8 | Doc Type: | No Doc Update |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2025-03-20 00:16:15 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 2334772 |
Description
Avinash Hanwate
2024-12-29 07:26:37 UTC
Indeed the vulnerable grub2 code seems to be embedded in radare2 Reported upstream: https://github.com/radareorg/radare2/issues/23848 FEDORA-EPEL-2025-c3c21f0192 (radare2-5.9.8-7.el10_1) has been submitted as an update to Fedora EPEL 10.1. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-c3c21f0192 FEDORA-EPEL-2025-5682727d1e (radare2-5.9.8-8.el8) has been submitted as an update to Fedora EPEL 8. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5682727d1e FEDORA-EPEL-2025-b3b0248eac (radare2-5.9.8-7.el9) has been submitted as an update to Fedora EPEL 9. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-b3b0248eac FEDORA-2025-1189bc2336 (radare2-5.9.8-7.fc42) has been submitted as an update to Fedora 42. https://bodhi.fedoraproject.org/updates/FEDORA-2025-1189bc2336 FEDORA-2025-f8eca89d63 (radare2-5.9.8-7.fc40) has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2025-f8eca89d63 FEDORA-2025-1189bc2336 has been pushed to the Fedora 42 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-1189bc2336` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-1189bc2336 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-EPEL-2025-c3c21f0192 has been pushed to the Fedora EPEL 10.1 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-c3c21f0192 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-EPEL-2025-b3b0248eac has been pushed to the Fedora EPEL 9 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-b3b0248eac See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2025-7b9adcd6ea has been pushed to the Fedora 41 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-7b9adcd6ea` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-7b9adcd6ea See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-EPEL-2025-5682727d1e has been pushed to the Fedora EPEL 8 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5682727d1e See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2025-f8eca89d63 has been pushed to the Fedora 40 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-f8eca89d63` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-f8eca89d63 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2025-1189bc2336 (radare2-5.9.8-7.fc42) has been pushed to the Fedora 42 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2025-7b9adcd6ea (radare2-5.9.8-7.fc41) has been pushed to the Fedora 41 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2025-f8eca89d63 (radare2-5.9.8-7.fc40) has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-EPEL-2025-c3c21f0192 (radare2-5.9.8-7.el10_1) has been pushed to the Fedora EPEL 10.1 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-EPEL-2025-b3b0248eac (radare2-5.9.8-7.el9) has been pushed to the Fedora EPEL 9 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-EPEL-2025-5682727d1e (radare2-5.9.8-8.el8) has been pushed to the Fedora EPEL 8 stable repository. If problem still persists, please make note of it in this bug report. |