CVE-2021-45078
published 2021-12-15CVE-2021-45078: stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have…
PriorityP334high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.31%
67.5th percentile
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.37.50.20220106-1 (bookworm) | binutils 2.37.50.20220106-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.37 | — |
| gnu | binutils | >= 0 < 2.37.50.20220106-1 | 2.37.50.20220106-1 |
| gnu | binutils | >= 0 < 2.37.50.20220106-1 | 2.37.50.20220106-1 |
| gnu | binutils | >= 0 < 2.37.50.20220106-1 | 2.37.50.20220106-1 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm3 | 2.26.1-1ubuntu1~16.04.8+esm3 |
| msrc | cbl2_binutils_2.37-3_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_binutils_2.36.1-2_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
binutils vulnerabilities
osv·2022-03-22·CVSS 7.8
CVE-2017-17122 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled checks for memory
allocation when parsing relocs in a corrupt file. An attacker could possibly
use this issue to cause a denial of service. (CVE-2017-17122)
It was discovered that GNU binutils incorrectly handled certain corrupt DWARF
debug sections. An attacker could possibly use this issue to cause GNU
binutils to consume memory, resulting in a denial of service. (CVE-2021-3487)
It was discovered that GNU binutils incorrectly performed bounds checking
operations when parsing stabs debugging information. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2021-45078)
GHSA
GHSA-wg2c-jc4j-gg9c: stab_xcoff_builtin_type in stabs
ghsa_unreviewed·2021-12-16·CVSS 9.8
CVE-2021-45078 [CRITICAL] CWE-787 GHSA-wg2c-jc4j-gg9c: stab_xcoff_builtin_type in stabs
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
OSV
CVE-2021-45078: stab_xcoff_builtin_type in stabs
osv·2021-12-15·CVSS 9.8
CVE-2021-45078 [CRITICAL] CVE-2021-45078: stab_xcoff_builtin_type in stabs
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Ubuntu
GNU binutils vulnerability
vendor_ubuntu·2023-06-13
CVE-2021-45078 GNU binutils vulnerability
Title: GNU binutils vulnerability
Summary: GNU binutils could be made to crash or run programs if it opened a
specially crafted file.
It was discovered that GNU binutils incorrectly performed bounds checking
operations when parsing stabs debugging information. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 7.8
CVE-2017-17122 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled checks for memory
allocation when parsing relocs in a corrupt file. An attacker could possibly
use this issue to cause a denial of service. (CVE-2017-17122)
It was discovered that GNU binutils incorrectly handled certain corrupt DWARF
debug sections. An attacker could possibly use this issue to cause GNU
binutils to consume memory, resulting in a denial of service. (CVE-2021-3487)
It was discovered that GNU binutils incorrectly performed bounds checking
operations when parsing stabs debugging information. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2021-45078)
Instructions: In
Red Hat
binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
vendor_redhat·2021-12-14·CVSS 9.8
CVE-2021-45078 [CRITICAL] CWE-787 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
An out-of-bounds flaw was found in binutils’ stabs functionality. The attack needs to be initiated locally where an attacker could convince a victim to read a specially crafted file that is processed by objdump, leading to the disclosure of memory and possibly leading to the execution of arbitrary code or causing the utility to crash.
Statement: The issue is classified as moderate severity primarily because binutils is not typ
Microsoft
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by
vendor_msrc·2021-12-14·CVSS 7.8
CVE-2021-45078 [CRITICAL] CWE-787 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blo
Debian
CVE-2021-45078: binutils - stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers...
vendor_debian·2021·CVSS 9.8
CVE-2021-45078 [CRITICAL] CVE-2021-45078: binutils - stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers...
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Scope: local
bookworm: resolved (fixed in 2.37.50.20220106-1)
bullseye: open
forky: resolved (fixed in 2.37.50.20220106-1)
sid: resolved (fixed in 2.37.50.20220106-1)
trixie: resolved (fixed in 2.37.50.20220106-1)
No detection rules found.
No public exploits indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQBH244M5PV6S6UMHUTCVCWFZDX7Y4M6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UUHLDDT3HH7YEY6TX7IJRGPJUTNNVEL3/https://security.gentoo.org/glsa/202208-30https://security.netapp.com/advisory/ntap-20220107-0002/https://sourceware.org/bugzilla/show_bug.cgi?id=28694https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=161e87d12167b1e36193385485c1f6ce92f74f02https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQBH244M5PV6S6UMHUTCVCWFZDX7Y4M6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UUHLDDT3HH7YEY6TX7IJRGPJUTNNVEL3/https://security.gentoo.org/glsa/202208-30https://security.netapp.com/advisory/ntap-20220107-0002/https://sourceware.org/bugzilla/show_bug.cgi?id=28694https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=161e87d12167b1e36193385485c1f6ce92f74f02
2021-12-15
Published