Automated vulnerability detection

Nick Clifton nickc@redhat.com
Tue Nov 8 12:47:10 GMT 2022


Hi Stephan,

> Do you use static analysis tools or fuzzers to test Binutils (2.29)?

Yes and no.  We - the GNU Biuntils project - do not use static analysers
or fuzzers directly.  But there are quite a few groups out there who do
use these tools to analyse the binutils sources and report problems that
they find.  We are always pleased to receive these reports and investigate
the issues that they find.

Aside - I assume that referring to version "2.29" in your email is a typo
and that you meant 2.39.  Version 2.29 is quite old now.


> We are happy to share any insights from our analysis which might be also helpful to you. Thank you very much in advance!

If you do find bugs in the binutils sources we are always happy to receive
them.  If you can, it really helps us if you are able to file bug reports
via the bur reporting system found here:

   https://sourceware.org/bugzilla/enter_bug.cgi?product=binutils

Cheers
   Nick



More information about the Binutils mailing list