binutils: NULL pointer dereference in _bfd_elf_get_symbol_version_string leads to segfault
Published Jan 27, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.44%
Description
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
Affected products
- Vendor n/a Product Binutils Defaultn/a
- Version binutils 2.39-7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Binutils | n/a |
|
Configuration 2
- 37
Configuration 3
- 6.0
- 7.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
binutils-0:2.30-119.el8_8.2
Fixed · RHSA-2023:6236
Red Hat Enterprise Linux 8
binutils-0:2.30-119.el8_8.2
Fixed · RHSA-2023:6236
Red Hat Enterprise Linux 8
gcc-toolset-12-binutils-0:2.38-17.el8
Fixed · RHSA-2023:2873
Red Hat Enterprise Linux 8.6 Extended Update Support
binutils-0:2.30-113.el8_6.2
Fixed · RHSA-2023:7394
Red Hat Enterprise Linux 9
binutils-0:2.35.2-42.el9
Fixed · RHSA-2023:6593
Red Hat Enterprise Linux 9
binutils-0:2.35.2-42.el9
Fixed · RHSA-2023:6593
Red Hat Software Collections for Red Hat Enterprise Linux 7
devtoolset-12-binutils-0:2.36.1-6.el7
Fixed · RHSA-2023:3269
Red Hat Enterprise Linux 6
binutils
Out of support scope
Red Hat Enterprise Linux 7
binutils
Will not fix
Red Hat Enterprise Linux 7
gdb
Will not fix
Red Hat Enterprise Linux 8
gcc-toolset-11-binutils
Will not fix
Red Hat Enterprise Linux 8
gcc-toolset-11-gdb
Will not fix
Red Hat Enterprise Linux 8
gcc-toolset-12-gdb
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-13-gdb
Not affected
Red Hat Enterprise Linux 9
gcc-toolset-12-gdb
Will not fix
Red Hat Enterprise Linux 9
gcc-toolset-13-gdb
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | binutils-0:2.30-119.el8_8.2 | Fixed | RHSA-2023:6236 |
| Red Hat Enterprise Linux 8 | binutils-0:2.30-119.el8_8.2 | Fixed | RHSA-2023:6236 |
| Red Hat Enterprise Linux 8 | gcc-toolset-12-binutils-0:2.38-17.el8 | Fixed | RHSA-2023:2873 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | binutils-0:2.30-113.el8_6.2 | Fixed | RHSA-2023:7394 |
| Red Hat Enterprise Linux 9 | binutils-0:2.35.2-42.el9 | Fixed | RHSA-2023:6593 |
| Red Hat Enterprise Linux 9 | binutils-0:2.35.2-42.el9 | Fixed | RHSA-2023:6593 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | devtoolset-12-binutils-0:2.36.1-6.el7 | Fixed | RHSA-2023:3269 |
| Red Hat Enterprise Linux 6 | binutils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | gdb | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-11-binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-11-gdb | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-12-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-13-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-12-gdb | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-13-gdb | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-4285 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2150768 ExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4285
- https://security.gentoo.org/glsa/202309-15 vendor-advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=29699 ExploitIssue TrackingPatchVendor Advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5c831a3c7f3ca98d6aba1200353311e1a1f84c70
- https://www.cve.org/CVERecord?id=CVE-2022-4285
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-4285 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2150768 | ExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4285 | ||
| https://security.gentoo.org/glsa/202309-15 | vendor-advisory | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=29699 | ExploitIssue TrackingPatchVendor Advisory | |
| https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70 | ||
| https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5c831a3c7f3ca98d6aba1200353311e1a1f84c70 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-4285 |
Change history (0)
No recorded changes yet.