This is the mail archive of the
binutils@sourceware.org
mailing list for the binutils project.
Re: RFA/RFC: Add stack recursion limit to libiberty's demangler
- From: Scott Gayou <sgayou at redhat dot com>
- To: nickc at redhat dot com
- Cc: ian at airs dot com, gcc-patches at gcc dot gnu dot org, binutils at sourceware dot org, matz at gcc dot gnu dot org, jason at redhat dot com
- Date: Thu, 29 Nov 2018 11:07:56 -0600
- Subject: Re: RFA/RFC: Add stack recursion limit to libiberty's demangler
- References: <87sgzkszbh.fsf@redhat.com>
Thank you for looking into this Nick. I've been staring at a few of these
CVEs off-and-on for a few days, and the following CVEs all look like
duplicates:
CVE-2018-17985: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87335
CVE-2018-18484: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87636
CVE-2018-18701: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87675
CVE-2018-18700: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87681
There may be more. I think Mitre is scanning the gnu bugzilla and assigning
CVEs? This does look like a legitimate very low criticality "denial of
service", but generating new CVEs for every unique poc file against the
same root cause doesn't seem useful. Perhaps some of these should be
rejected?
--
Scott Gayou / Red Had Product Security