Back

MEDIUM

binutils: memory leak in pr_function_type() in prdbg.c

Published Aug 22, 2023

Description

An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

Affected products

Remediation

Red Hat statement

The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The memory leak in pr_function_type only triggers during the parsing of malformed files, which would require an attacker to convince a user to process a malicious file. Moreover, binutils does not handle privileged operations, meaning exploitation is unlikely to lead to system compromise or escalation of privileges. Additionally, the impact is localized to the application itself, without affecting the broader system or network security.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 22, 2023
Updated Oct 3, 2024
Reserved Dec 12, 2022
CISA Vulnrichment
Updated Oct 3, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 18, 2022
ENISA EUVD
Assigner mitre
Published Aug 22, 2023
Updated Oct 3, 2024
Exploited since n/a
EUVD-2022-49788