VulnerabilityModified
CVE-2022-4285
Parsing an ELF file containing corrupt symbol version information may result in a denial of service.
MEDIUM 5.5EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- gnu/binutils · fedoraproject/fedora · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2150768Exploit, Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202309-15
- https://sourceware.org/bugzilla/show_bug.cgi?id=29699Exploit, Issue Tracking, Patch, Vendor Advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70
- https://bugzilla.redhat.com/show_bug.cgi?id=2150768Exploit, Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202309-15
- https://sourceware.org/bugzilla/show_bug.cgi?id=29699Exploit, Issue Tracking, Patch, Vendor Advisory
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.