CVE-2022-27943
published 2022-03-26CVE-2022-27943: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.89%
55.4th percentile
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gcc-12 | — | — |
| fedoraproject | fedora | — | — |
| gnu | gcc | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const
vendor_redhat·2022-03-26·CVSS 5.5
CVE-2022-27943 [MEDIUM] CWE-400 binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const
binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service.
Statement: The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The stack overflow i
Debian
CVE-2022-27943: gcc-12 - libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_c...
vendor_debian·2022·CVSS 5.5
CVE-2022-27943 [MEDIUM] CVE-2022-27943: gcc-12 - libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_c...
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
Scope: local
bookworm: open
forky: open
sid: open
trixie: open
GHSA
GHSA-xcrq-6rjw-5chw: libiberty/rust-demangle
ghsa_unreviewed·2022-03-27
CVE-2022-27943 [MEDIUM] CWE-400 GHSA-xcrq-6rjw-5chw: libiberty/rust-demangle
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
OSV
CVE-2022-27943: libiberty/rust-demangle
osv·2022-03-26·CVSS 5.5
CVE-2022-27943 [MEDIUM] CVE-2022-27943: libiberty/rust-demangle
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/https://sourceware.org/bugzilla/show_bug.cgi?id=28995https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/https://sourceware.org/bugzilla/show_bug.cgi?id=28995
2022-03-26
Published