Back

HIGH

Libdwarf: crashes randomly on fuzzed object

Published Mar 18, 2024

Description

A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

The double deallocation issue in libdwarf represents a moderate severity concern due to its potential to cause memory corruption and undefined behavior within the application. When memory is deallocated twice, it can lead to a range of unpredictable outcomes, including crashes, data corruption, and vulnerabilities that could be exploited maliciously. In a multi-threaded environment or in complex applications relying on libdwarf, such issues can be particularly challenging to diagnose and rectify. Additionally, the inconsistency in memory management can propagate errors across different parts of the software, complicating debugging efforts and potentially compromising the stability and security of the system..

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 18, 2024
Updated Nov 20, 2025
Reserved Feb 29, 2024
CISA Vulnrichment
Updated Aug 28, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 17, 2024