Input validation error in Binutils - CVE-2021-3487
Published: March 23, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the BFD library in binutils. A remote attacker who supplies a crafted file to an application linked with BFD can use the DWARF functionality to perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
IBM Cloud Pak for Watson AIOps
PowerStore T
PowerStore X
SUSE Linux Enterprise Module for Packagehub Subpackages
bpftrace-tools
bpftrace
binutils (Ubuntu package)
binutils-multiarch (Ubuntu package)
binutils (Red Hat package)
mingw-binutils
binutils-debugsource
binutils-debuginfo
binutils
binutils-devel
binutils-help
binutils-devel-32bit
libctf-nobfd0
libctf-nobfd0-debuginfo
libctf0
libctf0-debuginfo
binutils-gold-debuginfo
binutils-gold
cross-ppc-binutils
cross-ppc-binutils-debuginfo
cross-ppc-binutils-debugsource
cross-spu-binutils
cross-spu-binutils-debuginfo
cross-spu-binutils-debugsource
sys-libs/binutils-libs
sys-devel/binutils
How to mitigate CVE-2021-3487
bpftrace-tools - update to 0.11.4-3.2.1
bpftrace - update to 0.11.4-3.2.1
binutils (Ubuntu package) - addressed in versions 2.26.11ubuntu1~16.04.8+esm3, 2.30-21ubuntu1~18.04.7, 2.34-6ubuntu1.3
binutils-multiarch (Ubuntu package) - addressed in versions 2.26.11ubuntu1~16.04.8+esm3, 2.30-21ubuntu1~18.04.7, 2.34-6ubuntu1.3
binutils (Red Hat package) - update to 2.30-108.el8
mingw-binutils - addressed in versions 2.32-10.fc32, 2.34-8.fc33, 2.34-8.fc34
binutils-debugsource - update to 2.34-10
binutils-debuginfo - update to 2.34-10
binutils - update to 2.34-10
binutils-devel - update to 2.34-10
binutils-help - update to 2.34-10
binutils-devel-32bit - addressed in versions 2.37-6.23.1, 2.37-7.21.2
binutils - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-debugsource - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-devel - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf-nobfd0 - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf-nobfd0-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf0 - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
libctf0-debuginfo - addressed in versions 2.37-6.23.1, 2.37-7.21.2, 2.37-9.39.1
binutils-gold-debuginfo - addressed in versions 2.37-7.21.2, 2.37-9.39.1
binutils-gold - addressed in versions 2.37-7.21.2, 2.37-9.39.1
cross-ppc-binutils - update to 2.37-9.39.1
cross-ppc-binutils-debuginfo - update to 2.37-9.39.1
cross-ppc-binutils-debugsource - update to 2.37-9.39.1
cross-spu-binutils - update to 2.37-9.39.1
cross-spu-binutils-debuginfo - update to 2.37-9.39.1
cross-spu-binutils-debugsource - update to 2.37-9.39.1
sys-libs/binutils-libs - update to 2.38
sys-devel/binutils - update to 2.38
PowerStore T - update to 3.2.1.0-1989710
PowerStore X - update to 3.2.1.0-1989710
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=1947111
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q6V2LF5AVOUTHPYY2O5TRNAIXVMXFDGL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNBNDMJWZOQYCEZXENHBSM6DBZ332UZZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3Z3KSJY3CLAAFFT7FNFCJOMDITPQGN56/
Related Security Bulletins
- Denial of service in GNU Binutils
- Ubuntu update for binutils
- Gentoo update for GNU Binutils
- Red Hat Enterprise Linux 8 update for binutils
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler 20.03 LTS SP1 update for binutils
- SUSE update for binutils
- SUSE update for binutils
- SUSE update for binutils
- Ubuntu update for binutils
- Fedora 33 update for mingw-binutils
- Fedora 34 update for mingw-binutils
- Fedora 32 update for mingw-binutils