PT-2022-6748 · Gnu+6 · Gnu Binutils+6

Shuang Po

·

Published

2022-08-13

·

Updated

2026-01-30

·

CVE-2022-38533

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils versions prior to 2.4.0
Description The issue is related to a heap-buffer-overflow in the error function bfd getl32 when called from the strip main function in strip-new via a crafted file. This can lead to a denial of service. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For GNU Binutils versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted files that could trigger the heap-buffer-overflow in the bfd getl32 function. Restrict access to the strip-new function to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1379
ALT-PU-2023-4098
ALT-PU-2024-9331
AZL-10714
BDU:2023-03853
CLEANSTART-2026-HF39630
CVE-2022-38533
MGASA-2022-0425
OPENSUSE-SU-2022_4146-1
OPENSUSE-SU-2024:12631-1
SUSE-SU-2022:4146-1
SUSE-SU-2022:4277-1
USN-5762-1
USN-6544-1

Affected Products

Alt Linux
Astra Linux
Debian
Gnu Binutils
Linuxmint
Suse
Ubuntu