SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-4285

Parsing an ELF file containing corrupt symbol version information may result in a denial of service.

MEDIUM 5.5EPSS 0.44%

Does this matter?

Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.

Description

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
gnu/binutils · fedoraproject/fedora · redhat/enterprise linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.