Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Fedora 29: 2019-44a9d99647 Critical: elfutils Buffer Over-Read

fedora
Calendar Grey February 18, 2019
Scroller Fedora
An important patch for Fedora 29 tackles various elfutils vulnerabilities, enhancing the overall security and reliability of the system.
New upstream release 0.176

Summary

Elfutils is a collection of utilities, including stack (to show

backtraces), nm (for listing symbols from object files), size

(for listing the section sizes of an object or archive file),

strip (for discarding symbols), readelf (to see the raw ELF file

structures), elflint (to check for well-formed ELF files) and

elfcompress (to compress or decompress ELF sections).

New upstream release 0.176. Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149,

CVE-2019-7150, CVE-2019-7664 and CVE-2019-7665.

* Fri Feb 15 2019 Mark Wielaard - 0.176-1

- New upstream release.

- backends: riscv improved core file and return value location support.

- Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149, CVE-2019-7150,

CVE-2019-7664, CVE-2019-7665.

* Thu Jan 31 2019 Fedora Release Engineering - 0.175-3

- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild

* Mon Dec 3 2018 Mark Wielaard - 0.175-2

- Add elfutils-0.175-gnu-props-32.patch.

* Fri Nov 16 2018 Mark Wielaard - 0.175-1

- New upstream release.

- readelf: Handle multiple .debug_macro sections.

- strip: Add strip --reloc-debug-sections-only option.

Handle relocations against GNU compressed sections.

- libdwelf: New function dwelf_elf_begin.

- libcpu: Recognize bpf jump variants BPF_JLT, BPF_JLE, BPF_JSLT

and BPF_JSLE.

- backends: RISCV handles ADD/SUB relocations.

- Remove all patches.

* Wed Nov 14 2018 Mark Wielaard - 0.174-5

- Add elfutils-0.174-x86_64_unwind.patch.

- Add elfutils-0.174-gnu-property-note.patch.

- Add elfutils-0.174-version-note.patch.

- Add elfutils-0.174-gnu-attribute-note.patch

* Tue Nov 6 2018 Mark Wielaard - 0.174-4

- Add elfutils-0.174-size-rec-ar.patch

CVE-2018-18520 (#1646478)

- Add elfutils-0.174-ar-sh_entsize-zero.patch

CVE-2018-18521 (#1646483)

* Fri Nov 2 2018 Mark Wielaard - 0.174-3

- Add elfutils-0.174-libdwfl-sanity-check-core-reads.patch

CVE-2018-18310 (#1642605)

* Wed Oct 17 2018 Mark Wielaard - 0.174-2

- Add elfutils-0.174-strip-unstrip-group.patch.

[ 1 ] Bug #1671433 - CVE-2019-7146 elfutils: buffer over-read in the ebl_object_note function in eblobjnote.c in libebl [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1671433

[ 2 ] Bug #1671444 - CVE-2019-7149 elfutils: heap-based buffer over-read in read_srclines in dwarf_getsrclines.c in libdw [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1671444

[ 3 ] Bug #1677537 - CVE-2019-7664 elfutils: Out of bound write in elf_cvt_note in libelf/note_xlate.h [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1677537

[ 4 ] Bug #1677539 - CVE-2019-7665 elfutils: heap-based buffer over-read in function elf32_xlatetom in elf32_xlatetom.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1677539

[ 5 ] Bug #1677717 - elfutils-0.176 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1677717

su -c 'dnf upgrade --advisory FEDORA-2019-44a9d99647' at the command

line. For more information, refer to the dnf documentation available at

http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 0.176
Release: 1.fc29
Summary: A collection of utilities and DSOs to handle ELF files and DWARF data

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.