USN-6036-1: PatchELF vulnerability
20 April 2023
patchelf could be made to crash or read sensitive data if it opened a specially crafted file.
- patchelf - modify properties of ELF executables
It was discovered that PatchELF was not properly performing bounds
checks, which could lead to an out-of-bounds read via a specially
crafted file. An attacker could possibly use this issue to cause a
denial of service or to expose sensitive information. (CVE-2022-44940)