CVE-2023-25584
published 2023-09-14CVE-2023-25584: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
PriorityP425high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.38%
30.5th percentile
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.39.50.20221224-1 (bookworm) | binutils 2.39.50.20221224-1 (bookworm) |
| gnu | binutils | < 2.40 | 2.40 |
| gnu | binutils | >= 0 < 2.39.50.20221224-1 | 2.39.50.20221224-1 |
| gnu | binutils | >= 0 < 2.39.50.20221224-1 | 2.39.50.20221224-1 |
| gnu | binutils | >= 0 < 2.39.50.20221224-1 | 2.39.50.20221224-1 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9 | 2.30-21ubuntu1~18.04.9 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.5 | 2.34-6ubuntu1.5 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.2 | 2.38-4ubuntu2.2 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm1 | 2.24-5ubuntu14.2+esm1 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm6 | 2.26.1-1ubuntu1~16.04.8+esm6 |
| msrc | azl3_crash_8.0.4-3_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.3LOW
vendor_msrc6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-25584: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha
osv·2023-09-14·CVSS 7.1
CVE-2023-25584 [HIGH] CVE-2023-25584: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
GHSA
GHSA-xgv8-vx7r-x752: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha
ghsa_unreviewed·2023-09-14
CVE-2023-25584 [HIGH] CWE-125 GHSA-xgv8-vx7r-x752: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
OSV
binutils vulnerabilities
osv·2023-05-24·CVSS 7.8
CVE-2023-1579 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive information. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 2
Microsoft
Out of bounds read in parse_module function in bfd/vms-alpha.c
vendor_msrc·2023-09-12·CVSS 6.3
CVE-2023-25584 [MEDIUM] CWE-125 Out of bounds read in parse_module function in bfd/vms-alpha.c
Out of bounds read in parse_module function in bfd/vms-alpha.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: http
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-05-24·CVSS 7.8
CVE-2023-1972 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive informati
Debian
CVE-2023-25584: binutils - An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alp...
vendor_debian·2023·CVSS 6.3
CVE-2023-25584 [MEDIUM] CVE-2023-25584: binutils - An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alp...
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
Scope: local
bookworm: resolved (fixed in 2.39.50.20221224-1)
bullseye: open
forky: resolved (fixed in 2.39.50.20221224-1)
sid: resolved (fixed in 2.39.50.20221224-1)
trixie: resolved (fixed in 2.39.50.20221224-1)
Red Hat
binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c
vendor_redhat·2022-12-12·CVSS 6.3
CVE-2023-25584 [MEDIUM] CWE-125 binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c
binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
Statement: The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The buffer overflow in vms-alpha.c only triggers during the parsing of malformed files, which would require an attacker to convince a user to process a malicious binary file. Moreover, binutils does not handle privileged operations, meaning exploitation is unlikely to lead to system compromise or escalation of privileges. Additionally, the impa
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-25584 binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c
bugzilla·2023-02-06·CVSS 7.1
CVE-2023-25584 [HIGH] CVE-2023-25584 binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c
CVE-2023-25584 binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c
Out of bounds read flaws were found in Binutils in parse_module function in bfd/vms-alpha.c
Upstream fix:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=77c225bdeb410cf60da804879ad41622f5f1aa44
Discussion:
I don't think we build this in RHEL/Fedora binutils configurations. Nick, can you confirm?
---
(In reply to Siddhesh Poyarekar from comment #1)
> I don't think we build this in RHEL/Fedora binutils configurations. Nick,
> can you confirm?
Almost. We do not build it for Fedora (rawhide/f37/f36) or RHEL-9.
But we do build it for RHEL-8, RHEL-7 and RHEL-6. This is because,
for those targets, there is a problem with the configure script for
the gold linker when the s390x architecture i
Bugzilla
binutils: NULL pointer segmentation fault when accessing field `the_bfd` in function `compare_symbols`
bugzilla·2023-02-06·CVSS 7.1
CVE-2023-25584 [HIGH] binutils: NULL pointer segmentation fault when accessing field `the_bfd` in function `compare_symbols`
binutils: NULL pointer segmentation fault when accessing field `the_bfd` in function `compare_symbols`
In Binutils, there is a NULL pointer segmentation fault when accessing field `the_bfd` in function `compare_symbols`.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=29846
Upstream fix:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3d3af4ba39e892b1c544d667ca241846bc3df386
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-36 [bug 2174106]
Affects: fedora-37 [bug 2174108]
Affects: fedora-all [bug 2174098]
Created gdb tracking bugs for this issue:
Affects: fedora-36 [bug 2174107]
Created insight tracking bugs for this issue:
Affects: fedora-36 [bug 2174103]
Affects: fedora-37 [bug 2174109]
Created mingw-binutils tracking bug
https://access.redhat.com/security/cve/CVE-2023-25584https://bugzilla.redhat.com/show_bug.cgi?id=2167467https://security.netapp.com/advisory/ntap-20231103-0002/https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=77c225bdeb410cf60da804879ad41622f5f1aa44https://access.redhat.com/security/cve/CVE-2023-25584https://bugzilla.redhat.com/show_bug.cgi?id=2167467https://security.netapp.com/advisory/ntap-20231103-0002/https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=77c225bdeb410cf60da804879ad41622f5f1aa44
2023-09-14
Published