Out-of-bounds write in Binutils - CVE-2020-35448

 

Out-of-bounds write in Binutils - CVE-2020-35448

Published: December 27, 2020 / Updated: January 28, 2021


Vulnerability identifier: #VU50123
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35448
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.


Affected software

Binutils
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
mingw-w64-binutils (Alpine package)
SUSE Linux Enterprise Module for Packagehub Subpackages
bpftrace-tools
bpftrace
binutils (Red Hat package)
sys-devel/binutils
binutils-debuginfo
binutils
binutils-debugsource
binutils-devel
libctf-nobfd0
libctf-nobfd0-debuginfo
libctf0
libctf0-debuginfo
binutils-devel-32bit
binutils-gold-debuginfo
binutils-gold
cross-ppc-binutils
cross-ppc-binutils-debuginfo
cross-ppc-binutils-debugsource
cross-spu-binutils
cross-spu-binutils-debuginfo
cross-spu-binutils-debugsource
PowerStore X
PowerStore T

How to mitigate CVE-2020-35448

Install update from vendor's website.

mingw-w64-binutils (Alpine package) - update to 2.36-r0
bpftrace-tools - update to 0.11.4-3.2.1
bpftrace - update to 0.11.4-3.2.1
binutils (Red Hat package) - update to 2.30-108.el8
sys-devel/binutils - update to 2.35.2
binutils-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-debugsource - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-devel - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf-nobfd0 - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf-nobfd0-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf0 - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf0-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-devel-32bit - addressed in versions 2.37-6.23.1, 2.37-7.21.2
binutils-gold-debuginfo - addressed in versions 2.37-7.21.2, 2.37-9.39.1
binutils-gold - addressed in versions 2.37-7.21.2, 2.37-9.39.1
cross-ppc-binutils - update to 2.37-9.39.1
cross-ppc-binutils-debuginfo - update to 2.37-9.39.1
cross-ppc-binutils-debugsource - update to 2.37-9.39.1
cross-spu-binutils - update to 2.37-9.39.1
cross-spu-binutils-debuginfo - update to 2.37-9.39.1
cross-spu-binutils-debugsource - update to 2.37-9.39.1
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710

External References

Related Security Bulletins