CVE-2022-39170Double Free in Project Libdwarf

CWE-415Double Free6 documents6 sources
Severity
8.8HIGHNVD
EPSS
0.5%
top 33.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2
Latest updateSep 3

Description

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Also affects: Fedora 37

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q3xx-pg8c-jqh6: libdwarf 02022-09-03
OSV
CVE-2022-39170: libdwarf 02022-09-02
CVEList
CVE-2022-39170: libdwarf 02022-09-02

📋Vendor Advisories

2
Red Hat
libdwarf: double free in _dwarf_exec_frame_instr() in dwarf_frame.c2022-09-02
Debian
CVE-2022-39170: dwarfutils - libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.2022
CVE-2022-39170 — Double Free in Project Libdwarf | cvebase