PT-2022-6961 · Gnu+6 · Binutils+6

Published

2022-10-30

·

Updated

2025-01-28

·

CVE-2022-44840

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions binutils versions prior to 2.40
Description The issue is related to a heap buffer overflow in the readelf component of GNU Binutils, specifically in the find section in set() function within the readelf.c file. This occurs when processing ELF files. Exploitation of this issue could allow an attacker to execute arbitrary code or cause a denial of service.
Recommendations For binutils versions prior to 2.40, update to version 2.40 or later to resolve the issue. As a temporary workaround, consider restricting the use of the find section in set() function in readelf.c until a patch is available.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-9331
BDU:2023-05852
CVE-2022-44840
OPENSUSE-SU-2023_3825-1
OPENSUSE-SU-2024:13411-1
ROSA-SA-2025-2645
SUSE-SU-2023:3695-1
SUSE-SU-2023:3825-1
USN-6381-1
USN-6581-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Suse
Ubuntu
Binutils