Bug 2494416 (CVE-2026-13732)
| Summary: | CVE-2026-13732 gdb: gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in GDB's STABS debug format parser. The
read_member_functions() function in gdb/stabsread.c contains a linked
list removal bug in the code that separates destructor and non-destructor
member functions of C++ classes. The bug causes the destructor entries to
remain in the main function list while the list length counter is
decremented, resulting in an out-of-bounds write when the function list
is copied to its final allocated array. An attacker can craft an ELF
binary with malicious .stab and .stabstr sections that triggers this
out-of-bounds write when a user opens the file in GDB and performs any
symbol-inspection operation such as setting a breakpoint. The inferior
process does not need to be executed. Under controlled conditions, this
was demonstrated to achieve execution of arbitrary commands within the
GDB process.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2544475 | ||
| Bug Blocks: | |||
| Deadline: | 2026-08-06 | ||
A flaw was found in the GDB STABS debug format parser. The read_member_functions() function in gdb/stabsread.c processes C++ member function lists from STABS symbol data. When a class contains both destructor and non-destructor member functions, the code at lines 5086-5131 attempts to separate them into two lists. However, the linked list removal logic has a bug: the `last_sublist` tracking variable is updated to point to REMOVED destructor nodes instead of the previous retained node, and the `continue` path for non-destructor nodes does not update `last_sublist` at all. This causes destructor entries to remain in the `sublist` linked list while the `length` variable is decremented by `has_destructor`. In the subsequent copy loop (lines 5163-5166), the allocated array has `length` elements but the loop iterates over all remaining `sublist` entries (more than `length`). The loop index `i` starts at `length` and decrements, going negative, causing writes before the allocated obstack array. The written data consists of `struct fn_field` members controlled by the attacker through crafted STABS strings. The obstack underflow can corrupt chunk metadata including function pointers, which are called on subsequent obstack operations, resulting in arbitrary code execution. The vulnerability triggers automatically when GDB expands partial symbol tables — any symbol-inspection command (break, ptype, info functions) on a binary containing crafted .stab/.stabstr sections is sufficient. The inferior process does not need to be executed. Upstream: https://sourceware.org/git/binutils-gdb.git Affected: gdb/stabsread.c (read_member_functions, lines 5086-5166) Confirmed on: GDB 16.3-1, Debian trixie, x86-64, glibc 2.41 Reporter: JD Marsters (Bhut Red)