Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Fedora 37 FEDORA-2022-273a86adf0 Critical: Libdwarf Double Free

fedora
Calendar Grey September 17, 2022
Dist Fedora Esm H88
Upgrade libdwarf to version 0.4.2 in Fedora 37 to fix a significant double free vulnerability. Use dnf for installation.
Update to latest upstream release

Summary

Library to access the DWARF debugging file format which supports

source level debugging of a number of procedural languages, such as C, C++,

and Fortran. Please see https://dwarfstd.org/ for DWARF specification.

Update to latest upstream release

* Tue Sep 13 2022 Tom Hughes - 1:0.4.2-1

- Update to 0.4.2 upstream release

[ 1 ] Bug #2126426 - CVE-2022-39170 libdwarf: double free in _dwarf_exec_frame_instr() in dwarf_frame.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2126426

[ 2 ] Bug #2126518 - libdwarf-0.4.2 is available

https://bugzilla.redhat.com/show_bug.cgi?id=2126518

su -c 'dnf upgrade --advisory FEDORA-2022-273a86adf0' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 0.4.2
Release: 1.fc37
Summary: Library to access the DWARF Debugging file format

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here