Bug 2438919 - CVE-2026-2341 sdcc: libiberty: Application crash via crafted C++ symbol demangling [fedora-all]
Summary: CVE-2026-2341 sdcc: libiberty: Application crash via crafted C++ symbol deman...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: sdcc
Version: 43
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Jiri Kastner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["038ae367-c1c0-466b-afa1-b...
Depends On:
Blocks: CVE-2026-2341
TreeView+ depends on / blocked
 
Reported: 2026-02-11 13:33 UTC by Michal Findra
Modified: 2026-03-16 22:49 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Michal Findra 2026-02-11 13:33:24 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Roy Rankin 2026-03-16 22:49:03 UTC
Although I see no evidence that this is an issue, I do not know how it might be triggered, so I cannot test it. I asked a similar question about gputils and have not gotten any response. I also do not know what is meant by "starting the update process" as this package looks to be updated to F44. Note that sdcc and gputils use the same code.


Note You need to log in before you can comment on or make changes to this bug.