CVE-2021-3530
published 2021-06-02CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.40%
82.2th percentile
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.37.90.20220207-1 (bookworm) | binutils 2.37.90.20220207-1 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.37.90.20220207-1 | 2.37.90.20220207-1 |
| gnu | binutils | >= 0 < 2.37.90.20220207-1 | 2.37.90.20220207-1 |
| gnu | binutils | >= 0 < 2.37.90.20220207-1 | 2.37.90.20220207-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54mp-4694-9j92: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle
ghsa_unreviewed·2022-05-24
CVE-2021-3530 [HIGH] CWE-674 GHSA-54mp-4694-9j92: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
OSV
CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle
osv·2021-06-02·CVSS 7.5
CVE-2021-3530 [HIGH] CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Red Hat
binutils: infinite loop while demangling rust symbols
vendor_redhat·2021-06-08·CVSS 7.5
CVE-2021-3648 [HIGH] CWE-835 binutils: infinite loop while demangling rust symbols
binutils: infinite loop while demangling rust symbols
[REJECTED CVE] A flaw was discovered in GNU libiberty as distributed in GNU Binutils. A crafted file can cause an infinite loop leading to a stack overflow and crash.
Statement: This flaw was found to be a duplicate of CVE-2021-3530. Please see https://access.redhat.com/security/cve/CVE-2021-3530 for information about affected products and security errata.
Package: binutils (Red Hat Enterprise Linux 6) - Not affected
Package: binutils (Red Hat Enterprise Linux 7) - Not affected
Package: binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-10-binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-9-binutils (Red Hat Enterprise Linux 8) - Not affected
Package: binutils (Red Hat Enterprise Li
Red Hat
binutils: stack memory exhaustion in demangle_path() in rust-demangle.c
vendor_redhat·2021-04-21·CVSS 7.5
CVE-2021-3530 [HIGH] CWE-674 binutils: stack memory exhaustion in demangle_path() in rust-demangle.c
binutils: stack memory exhaustion in demangle_path() in rust-demangle.c
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Package: binutils (Red Hat Enterprise Linux 6) - Not affected
Package: binutils (Red Hat Enterprise Linux 7) - Not affected
Package: binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-10-binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-9-binutils (Red Hat Enterprise
Debian
CVE-2021-3530: binutils - A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c...
vendor_debian·2021·CVSS 7.5
CVE-2021-3530 [HIGH] CVE-2021-3530: binutils - A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c...
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
Scope: local
bookworm: resolved (fixed in 2.37.90.20220207-1)
bullseye: open
forky: resolved (fixed in 2.37.90.20220207-1)
sid: resolved (fixed in 2.37.90.20220207-1)
trixie: resolved (fixed in 2.37.90.20220207-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1956423https://security.gentoo.org/glsa/202208-30https://security.netapp.com/advisory/ntap-20210716-0006/https://src.fedoraproject.org/rpms/binutils/blob/rawhide/f/binutils-CVE-2021-3530.patchhttps://bugzilla.redhat.com/show_bug.cgi?id=1956423https://security.gentoo.org/glsa/202208-30https://security.netapp.com/advisory/ntap-20210716-0006/https://src.fedoraproject.org/rpms/binutils/blob/rawhide/f/binutils-CVE-2021-3530.patch
2021-06-02
Published