CVE-2021-3530 — Uncontrolled Recursion in Binutils
Severity
7.5HIGHNVD
EPSS
0.4%
top 42.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 2
Latest updateMay 24
Description
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-54mp-4694-9j92: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle↗2022-05-24
CVEList▶
CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle↗2021-06-02
OSV▶
CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle↗2021-06-02