Search CVE reports
31 – 40 of 237 results
CVE-2022-27943
Low prioritylibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
52 affected packages
binutils, crash, gcc-10, gcc-11, gcc-12...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | Not affected | Vulnerable | Not affected | Not affected | Not affected |
crash | Not affected | Not affected | Not affected | Not affected | Not affected |
gcc-10 | Not affected | Not affected | Not affected | Not in release | Not in release |
gcc-11 | Vulnerable | Vulnerable | Not in release | Not in release | Not in release |
gcc-12 | Vulnerable | Vulnerable | Not in release | Not in release | Not in release |
gcc-13 | Not affected | Not in release | Not in release | Not in release | Not in release |
gcc-3.3 | Not affected | Not affected | Not affected | Not affected | Needs evaluation |
gcc-4.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-4.6 | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-4.7 | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.7-armel-cross | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.7-armhf-cross | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.8 | Not in release | Not in release | Not in release | Not affected | Not affected |
gcc-4.8-arm64-cross | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.8-armhf-cross | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.8-powerpc-cross | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.8-ppc64el-cross | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-4.9 | Not in release | Not in release | Not in release | Not in release | Not affected |
gcc-5 | Not in release | Not in release | Not in release | Not affected | Not affected |
gcc-5-cross | Not in release | Not in release | Not in release | Not affected | Not affected |
gcc-6 | Not in release | Not in release | Not in release | Not affected | Not in release |
gcc-6-cross | Not in release | Not in release | Not in release | Not affected | Not in release |
gcc-6-cross-ports | Not in release | Not in release | Not in release | Not affected | Not in release |
gcc-7 | Not in release | Not in release | Not affected | Not affected | Not in release |
gcc-7-cross | Not in release | Not in release | Not in release | Needs evaluation | Not in release |
gcc-7-cross-ports | Not in release | Not in release | Not in release | Needs evaluation | Not in release |
gcc-8 | Not in release | Not in release | Not affected | Not affected | Not in release |
gcc-8-cross | Not in release | Not in release | Needs evaluation | Needs evaluation | Not in release |
gcc-8-cross-ports | Not in release | Not in release | Not affected | Not affected | Not in release |
gcc-9 | Not affected | Not affected | Not affected | Not in release | Not in release |
gcc-9-cross | Not affected | Not affected | Not affected | Not in release | Not in release |
gcc-9-cross-ports | Not affected | Not affected | Not affected | Not in release | Not in release |
gcc-arm-linux-androideabi | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-arm-none-eabi | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-avr | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-defaults | Not affected | Not affected | Not affected | Not affected | Not affected |
gcc-defaults-arm64-cross | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-defaults-armel-cross | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-defaults-armhf-cross | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-defaults-powerpc-cross | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-defaults-ppc64el-cross | Not in release | Not in release | Not in release | Not in release | Not in release |
gcc-h8300-hms | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-i686-linux-android | Not in release | Not in release | Not in release | Not in release | Needs evaluation |
gcc-m68hc1x | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-mingw-w64 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-msp430 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-opt | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
gcc-snapshot | Not affected | Ignored | Ignored | Not affected | Not affected |
gccgo-4.9 | Not in release | Not in release | Not in release | Not in release | Not in release |
gccgo-6 | Not in release | Not in release | Not in release | Not in release | Not affected |
gdb | Not affected | Vulnerable | Not affected | Not affected | Not affected |
libiberty | Not affected | Vulnerable | Not affected | Not affected | Not affected |
CVE-2021-45078
Low prioritySome fixes available 2 of 6
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE:...
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | Not affected | Not affected | Fixed | Vulnerable | Fixed |
CVE-2021-37322
Negligible prioritySome fixes available 1 of 3
GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | Not affected | Not affected | Not affected | Not affected | Fixed |
CVE-2021-3530
Low prioritySome fixes available 1 of 6
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
3 affected packages
binutils, gdb, libiberty
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | Not affected | Not affected | Not affected | Not affected | Not affected |
gdb | Not affected | Fixed | Not affected | Not affected | Not affected |
libiberty | Not affected | Vulnerable | Not affected | Not affected | Not affected |
CVE-2021-3549
Low prioritySome fixes available 2 of 3
An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory...
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | — | Fixed | Not affected | Not affected | Not affected |
CVE-2021-20294
Negligible priorityA flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the...
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | — | Not affected | Not affected | Not affected | Not affected |
CVE-2021-20284
Low priorityA flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from...
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | — | Not affected | Not affected | Not affected | Not affected |
CVE-2021-20197
Low priorityThere is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script...
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | — | Not affected | Ignored | Ignored | Ignored |
CVE-2020-35507
Low priorityThere's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference....
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | — | Not affected | Not affected | Not affected | Not affected |
CVE-2020-35496
Low priorityThere's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this...
1 affected package
binutils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
binutils | — | Not affected | Not affected | Not affected | Not affected |