gdb-16.3-3.1.el9_8
エラータID: AXSA:2026-1945:02
The GNU Debugger (GDB) allows you to debug programs written in C, C++, Java,
and other languages by executing them in a controlled fashion and then
printing out their data.
Security Fix(es):
* gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (CVE-2026-13732)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
CVE-2026-13732
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
Update packages.
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
N/A
SRPMS
- gdb-16.3-3.1.el9_8.src.rpm
MD5: 5796bc335ed1ef21a8dbfd16439edf67
SHA-256: 2bd3e54ea6127f41a1baa402e2ea367fdd63449d606ba548b00b2426c2fd8098
Size: 23.46 MB
Asianux Server 9 for x86_64
- gdb-16.3-3.1.el9_8.x86_64.rpm
MD5: a00aa5f5f88c88727cb9abba43b29302
SHA-256: 06be45d95759f050d5f765855d52ff0ebb93ab2c0f325d47749d56da460e807d
Size: 139.86 kB - gdb-doc-16.3-3.1.el9_8.noarch.rpm
MD5: d2040659d6f9c5f75ac2cdf2f600b8ac
SHA-256: 1a52035281fb65ee08b0aeaa6ed7bfa42af23316f6d8a422f8efa00a91fce7a6
Size: 3.69 MB - gdb-gdbserver-16.3-3.1.el9_8.x86_64.rpm
MD5: 01a263d42b71adf6a35a84ce3354ee14
SHA-256: f18da11beaf5ecbf6937adfd30291410f2d6d70ce865234170c9482233fe5c31
Size: 321.69 kB - gdb-headless-16.3-3.1.el9_8.x86_64.rpm
MD5: 702ee1ee0c0f9c6aafc25f03e71a43e2
SHA-256: f0e8f7628af052a070c10ffcf5d8989a55ff1f087dbca405a4d458b539a97702
Size: 5.07 MB - gdb-minimal-16.3-3.1.el9_8.x86_64.rpm
MD5: cff924151af08b54da1619dee98681c5
SHA-256: 2ed51a7327bde3b6a737ba38e1f3e0c83367e4a6cd53f54ea80755987ebb7e5d
Size: 4.40 MB