This was privately disclosed to vapier which invited me to file a bug here. I found multiple FPE on dumpelf. Since I cannot obtain a valid asan/gdb trace, is not clear to me if this is just one issue with duplicates or not. All issues are reproducible with "dumpelf $FILE" 1) FPE on unknown address 0x00000051ca65 (pc 0x00000051ca65 bp 0x7ffc31bb6f80 sp 0x7ffc31bb6e40 T0) Reproducer: https://github.com/asarubbo/poc/blob/master/00137-pax-utils-dumpelf-fpe1 2) FPE on unknown address 0x00000051d335 (pc 0x00000051d335 bp 0x7ffc17babf80 sp 0x7ffc17babe40 T0) Reproducer: https://github.com/asarubbo/poc/blob/master/00138-pax-utils-dumpelf-fpe2 3) FPE on unknown address 0x00000051db76 (pc 0x00000051db76 bp 0x7ffdf90fff80 sp 0x7ffdf90ffe40 T0) Reproducer: https://github.com/asarubbo/poc/blob/master/00139-pax-utils-dumpelf-fpe3 If you need something else feel free to ask.
should be fixed here: https://gitweb.gentoo.org/proj/pax-utils.git/commit/?id=4609f57a690b4a5670baeb93167dab5300d07d4e not planning on doing an update right away since dumpelf is a programming tool that no one really runs directly
(In reply to SpanKY from comment #1) > should be fixed here: > https://gitweb.gentoo.org/proj/pax-utils.git/commit/ > ?id=4609f57a690b4a5670baeb93167dab5300d07d4e > > not planning on doing an update right away since dumpelf is a programming > tool that no one really runs directly Vapier, just a tickler to see if you are ready for the bug now.
just to confirm, git describe --tags 4609f57a690b4a5670baeb93167dab5300d07d4e v1.2.2-1-g4609f57
Fixed with app-misc/pax-utils-1.2.3 and newer.
GLSA Vote: No