Resource exhaustion in Binutils - CVE-2018-12641
Published: June 22, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args, and demangle_nested_args. This can occur during execution of nm-new.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
binutils (Red Hat package)
Data Computing Appliance (DCA)
How to mitigate CVE-2018-12641
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
- https://access.redhat.com/errata/RHSA-2019:2075
- https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763099
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85452
- https://security.gentoo.org/glsa/201908-01
- https://sourceware.org/bugzilla/show_bug.cgi?id=23058
- https://usn.ubuntu.com/4326-1/
- https://usn.ubuntu.com/4336-1/