Bug 2450317
| Summary: | CVE-2026-4647 gdb: Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Abhishek Raj <abhraj> |
| Component: | gdb | Assignee: | Kevin Buettner <kevinb> |
| Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | rawhide | CC: | ahajkova, fweimer, guinevere, jan, keiths, kevinb, mcermak, mkolar, suraj.ghimire7 |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["1042e5e4-7ebc-44fa-8e5f-b82f96055fd6"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-03-24 19:00:40 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2450302 | ||
|
Description
Abhishek Raj
2026-03-23 13:06:00 UTC
Closing, as GDB is not affected by this problem. The upstream fix posted by Alan Modra is to xcoff_ppc_relocate_section() and xcoff64_ppc_relocate_section() in bfd/coff-rs6000.c and bfd/coff64-rs6000.c. These functions are part of the BFD XCOFF linker backend and are only called during linking operations. GDB reads XCOFF binaries for symbol and debug information but does not perform linking or relocation processing, so it never calls these functions. Additionally, this vulnerability would not affect Fedora systems regardless, as Fedora uses the ELF format rather than XCOFF. |