binutils: memory leak in pr_function_type() in prdbg.c
Published Aug 22, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.39%
Description
An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
binutils
Out of support scope
Red Hat Enterprise Linux 7
binutils
Out of support scope
Red Hat Enterprise Linux 7
gdb
Out of support scope
Red Hat Enterprise Linux 8
binutils
Will not fix
Red Hat Enterprise Linux 8
gcc-toolset-11-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-11-gdb
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-12-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-12-gdb
Not affected
Red Hat Enterprise Linux 8
gcc-toolset-13-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-13-gdb
Affected
Red Hat Enterprise Linux 8
gdb
Affected
Red Hat Enterprise Linux 8
mingw-binutils
Fix deferred
Red Hat Enterprise Linux 9
binutils
Will not fix
Red Hat Enterprise Linux 9
gcc-toolset-12-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-12-gdb
Not affected
Red Hat Enterprise Linux 9
gcc-toolset-13-binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-13-gdb
Not affected
Red Hat Enterprise Linux 9
gdb
Affected
Red Hat Enterprise Linux 9
mingw-binutils
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | binutils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | binutils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gdb | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-11-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-11-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-12-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-12-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-13-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-13-gdb | Affected | n/a |
| Red Hat Enterprise Linux 8 | gdb | Affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | binutils | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-12-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-12-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-13-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-13-gdb | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gdb | Affected | n/a |
| Red Hat Enterprise Linux 9 | mingw-binutils | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The memory leak in pr_function_type only triggers during the parsing of malformed files, which would require an attacker to convince a user to process a malicious file. Moreover, binutils does not handle privileged operations, meaning exploitation is unlikely to lead to system compromise or escalation of privileges. Additionally, the impact is localized to the application itself, without affecting the broader system or network security.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-47010 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2233988 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-49788 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-47010
- https://sourceware.org/bugzilla/show_bug.cgi?id=29262 ExploitIssue TrackingThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-47010
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-47010 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2233988 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-49788 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-47010 | ||
| https://sourceware.org/bugzilla/show_bug.cgi?id=29262 | ExploitIssue TrackingThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-47010 |
Change history (0)
No recorded changes yet.