« List of all CVEs

CVE-2023-25588

Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab`

Published: 9/14/2023 Last updated: 2/13/2025 Reserved: 2/7/2023

A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 4.7 Medium CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Opam packages affected (3)

bap-std clangml conf-binutils

Products affected (19)

Product Vendor Version
Red Hat Enterprise Linux 8 Red Hat 17.3.1
Fedora 36 Fedora < J10.19.050004
Red Hat Enterprise Linux 7 Red Hat 17.2.1a
Red Hat Enterprise Linux 6 Red Hat 17.2.1
Red Hat Enterprise Linux 9 Red Hat 17.3.4
Fedora Fedora 17.5.1
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat 17.3.2a
Red Hat Enterprise Linux 9 Red Hat < H10.19.050004
Fedora 36 Fedora 17.6.5
Fedora 37 Fedora n/a
Fedora 36 Fedora 17.6.6a
Fedora 37 Fedora n/a
Fedora 37 Fedora 17.6.2
Extra Packages for Enterprise Linux 7 Fedora n/a
Extra Packages for Enterprise Linux 8 Fedora 17.3.7
Fedora 36 Fedora < 17.7
Extra Packages for Enterprise Linux 8 Fedora n/a
binutils n/a 17.1.3

References (10)