Fedora Account System
Red Hat Associate
Red Hat Customer
There's a flaw in binutils 2.46.1 in rsrc_print_name() and rsrc_parse_entries() functions by which an attacker with local access or whom does not have local access but social engineers a victim to run binutils on a crafted PE file, can execute malicious code.
There is no impact to Confidential, Integrity, or Availability due to upstream security policy which explicitly states that no security boundary is crossed in the case of this bug.
Fix upstream by commit eda3758e23c Will be brought in to rawhide as part of the next rebase of the binutils package.