On Sun, 2026-07-19 at 22:43 +0200, Yoann Congal wrote: > Hello, > > On Thu Jul 16, 2026 at 11:58 AM CEST, Roland Kovács via > lists.openembedded.org wrote: > > Binutils objdump contains a denial-of-service vulnerability when processing > > a crafted binary with malformed DWARF debug information. A logic error in > > the handling of DWARF compilation units can result in an invalid offset_size > > value being used inside byte_get_little_endian, leading to an abort > > (SIGABRT). > > A local attacker can trigger the crash by supplying a malicious input file. > > > > Signed-off-by: Roland Kovacs <[email protected]> > > --- > > .../binutils/binutils-2.42.inc | 1 + > > .../binutils/binutils/CVE-2025-69645.patch | 135 ++++++++++++++++++ > > 2 files changed, 136 insertions(+) > > create mode 100644 > > meta/recipes-devtools/binutils/binutils/CVE-2025-69645.patch > > More than a description of the vulnerability, what we need in the commit > message is a justification for the patch: i.e. why this is the patch we > should take to fix this CVE? In this case, this is trivial, this is the > patch referenced from the NVD page, so I've added it. I'll keep this in mind, thanks.
> > Also, the NVD entry looks wrong: only the 2.44 version is said impacted > but the patches to fix apply way more than that. NVD data marks any version affected, 2.44 is __mentioned__ in the description but no filter or bound is set in the CVE metadata. > Can you reach them and fix the NVD data? I can ask upstream who issued the CVE to set 2.46 as unaffected/fixed based on their bugtracker, but that's about it. > > Thanks!
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241351): https://lists.openembedded.org/g/openembedded-core/message/241351 Mute This Topic: https://lists.openembedded.org/mt/120296032/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
