Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2023-25588

Published: 15 February 2023

binutils: Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab`

Notes

AuthorNote
seth-arnold
binutils isn't safe for untrusted inputs.

Priority

Medium

Status

Package Release Status
binutils
Launchpad, Ubuntu, Debian
bionic
Released (2.30-21ubuntu1~18.04.9)
focal
Released (2.34-6ubuntu1.5)
jammy
Released (2.38-4ubuntu2.2)
kinetic
Released (2.39-3ubuntu1.2)
lunar Not vulnerable
(2.40-2ubuntu4)
trusty
Released (2.24-5ubuntu14.2+esm1)
upstream Needs triage

xenial
Released (2.26.1-1ubuntu1~16.04.8+esm6)