CVE-2023-25586
published 2023-09-14CVE-2023-25586: A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a…
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.35%
27.2th percentile
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.39.50.20221208-1 (bookworm) | binutils 2.39.50.20221208-1 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.39.50.20221208-1 | 2.39.50.20221208-1 |
| gnu | binutils | >= 0 < 2.39.50.20221208-1 | 2.39.50.20221208-1 |
| gnu | binutils | >= 0 < 2.39.50.20221208-1 | 2.39.50.20221208-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gpjh-j7vh-fwmj: A flaw was found in Binutils
ghsa_unreviewed·2023-09-14
CVE-2023-25586 [MEDIUM] CWE-908 GHSA-gpjh-j7vh-fwmj: A flaw was found in Binutils
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
OSV
CVE-2023-25586: A flaw was found in Binutils
osv·2023-09-14·CVSS 5.5
CVE-2023-25586 [MEDIUM] CVE-2023-25586: A flaw was found in Binutils
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
Debian
CVE-2023-25586: binutils - A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_st...
vendor_debian·2023·CVSS 4.7
CVE-2023-25586 [MEDIUM] CVE-2023-25586: binutils - A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_st...
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
Scope: local
bookworm: resolved (fixed in 2.39.50.20221208-1)
bullseye: open
forky: resolved (fixed in 2.39.50.20221208-1)
sid: resolved (fixed in 2.39.50.20221208-1)
trixie: resolved (fixed in 2.39.50.20221208-1)
Red Hat
binutils: Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitialized
vendor_redhat·2022-12-12·CVSS 4.7
CVE-2023-25586 [MEDIUM] CWE-457 binutils: Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitialized
binutils: Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitialized
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
Package: binutils (Red Hat Enterprise Linux 6) - Not affected
Package: binutils (Red Hat Enterprise Linux 7) - Not affected
Package: gdb (Red Hat Enterprise Linux 7) - Not affected
Package: binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-11-binutils (Red Hat Enterprise Li
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2023-25586https://bugzilla.redhat.com/show_bug.cgi?id=2167502https://security.netapp.com/advisory/ntap-20231103-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=29855https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5830876a0cca17bef3b2d54908928e72cca53502https://access.redhat.com/security/cve/CVE-2023-25586https://bugzilla.redhat.com/show_bug.cgi?id=2167502https://security.netapp.com/advisory/ntap-20231103-0003/https://sourceware.org/bugzilla/show_bug.cgi?id=29855https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5830876a0cca17bef3b2d54908928e72cca53502
2023-09-14
Published