Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635860 (CVE-2017-15996) - <sys-devel/binutils-2.29.1-r1: remote denial of service via crafted ELF file
Summary: <sys-devel/binutils-2.29.1-r1: remote denial of service via crafted ELF file
Alias: CVE-2017-15996
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Whiteboard: A3 [glsa cve]
Depends on:
Reported: 2017-10-30 00:42 UTC by Aleksandr Wagner (Kivak)
Modified: 2018-01-07 23:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-10-30 00:42:10 UTC
CVE-2017-15996 (

elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that triggers a "buffer overflow on fuzzed archive header," related to an uninitialized variable, an improper conditional jump, and the get_archive_member_name, process_archive_index_and_symbols, and setup_archive functions. 

Comment 1 Mike Gilbert gentoo-dev 2017-10-30 00:50:23 UTC
How is this a *remote* DOS if it requires reading an ELF file?
Comment 2 Andreas K. Hüttel archtester gentoo-dev 2017-10-30 00:54:56 UTC
That's something I don't understand either...
Comment 3 Andreas K. Hüttel archtester gentoo-dev 2017-11-17 22:44:52 UTC
In master, will be in 2.30; patch added to gentoo/binutils-2.29.1 branch
Comment 4 Andreas K. Hüttel archtester gentoo-dev 2017-12-27 22:56:39 UTC
All affected versions are masked. No further cleanup (toolchain package). 

Nothing to do for toolchain here anymore. Please proceed.
Comment 5 D'juan McDonald (domhnall) 2018-01-05 06:49:12 UTC
Added to existing GLSA request.

Gentoo Security Padawan
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2018-01-07 23:12:47 UTC
This issue was resolved and addressed in
 GLSA 201801-01 at
by GLSA coordinator Aaron Bauman (b-man).