USN-6036-1: PatchELF vulnerability
20 April 2023
patchelf could be made to crash or read sensitive data if it opened a specially crafted file.
Releases
Packages
- patchelf - modify properties of ELF executables
Details
It was discovered that PatchELF was not properly performing bounds
checks, which could lead to an out-of-bounds read via a specially
crafted file. An attacker could possibly use this issue to cause a
denial of service or to expose sensitive information. (CVE-2022-44940)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
-
patchelf
-
0.14.3-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.