CVE-2022-39170
published 2022-09-02CVE-2022-39170: libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.94%
56.9th percentile
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dwarfutils | — | — |
| fedoraproject | fedora | — | — |
| libdwarf_project | libdwarf | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q3xx-pg8c-jqh6: libdwarf 0
ghsa_unreviewed·2022-09-03
CVE-2022-39170 [HIGH] CWE-415 GHSA-q3xx-pg8c-jqh6: libdwarf 0
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
OSV
CVE-2022-39170: libdwarf 0
osv·2022-09-02·CVSS 8.8
CVE-2022-39170 [HIGH] CVE-2022-39170: libdwarf 0
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
Red Hat
libdwarf: double free in _dwarf_exec_frame_instr() in dwarf_frame.c
vendor_redhat·2022-09-02·CVSS 8.8
CVE-2022-39170 [HIGH] CWE-415 libdwarf: double free in _dwarf_exec_frame_instr() in dwarf_frame.c
libdwarf: double free in _dwarf_exec_frame_instr() in dwarf_frame.c
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
A double-free vulnerability was found in libdwarf's dwarf_expand_frame_instructions() function of the dwarf_frame.c file. A carefully crafted object file could cause the ‘dwarfdump' utility to do a double free in handling an error condition. This issue could cause a segmentation violation or other major error, terminating the calling application and resulting in a denial of service.
Statement: The vulnerable code was introduced upstream in libdwarf-0.3.0, and later, Red Hat ships lower versions of libdwarf, which do not contain the vulnerable code. Hence, versions of libdwarf shipped with Red Hat Enterprise Linux 7 & 8 are not affected by this
Debian
CVE-2022-39170: dwarfutils - libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
vendor_debian·2022·CVSS 8.8
CVE-2022-39170 [HIGH] CVE-2022-39170: dwarfutils - libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/davea42/libdwarf-code/commit/60303eb80ecc7747bf29776d545e2a5c5a76f6f8https://github.com/davea42/libdwarf-code/issues/132https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IKUE4XT62AEZ3H5D6GMREYOSCMMRFXBH/https://github.com/davea42/libdwarf-code/commit/60303eb80ecc7747bf29776d545e2a5c5a76f6f8https://github.com/davea42/libdwarf-code/issues/132https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IKUE4XT62AEZ3H5D6GMREYOSCMMRFXBH/
2022-09-02
Published