Updated: 2025-08-20 02:05:47.287272
Description:
The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address exceeds its own memory region, resulting in an out-of-bounds memory write, as demonstrated by objcopy copying private info with _bfd_pex64_bfd_copy_private_bfd_data_common in pex64igen.c.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | MEDIUM | 4.3 |
| CVSS Version 3.x | MEDIUM | 5.5 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| CentOS 6 ELS | binutils | 2.20 | 5.5 | MEDIUM | Not Vulnerable | 2021-12-16 10:40:05 | ||
| CloudLinux 6 ELS | binutils | 2.20 | 5.5 | MEDIUM | Not Vulnerable | 2021-12-16 10:40:05 | ||
| Oracle Linux 6 ELS | binutils | 2.20 | 5.5 | MEDIUM | Not Vulnerable | 2021-12-16 10:40:05 | ||
| Ubuntu 16.04 ELS | binutils | 2.26 | 5.5 | MEDIUM | Released | CLSA-2021:1635459139 | 2021-12-16 10:40:05 |