gdb-8.2-20.1.el8_10
エラータID: AXSA:2026-1966:03
The GNU Debugger (GDB) allows debugging programs written in C, C++, Java, and
other languages by executing them in a controlled fashion and then printing
their data.
Security Fix(es):
* gdb: STABS debug format parser out-of-bounds write via crafted ELF binary (CVE-2026-13732)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
CVE-2026-13732
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
Update packages.
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.
N/A
SRPMS
- gdb-8.2-20.1.el8_10.src.rpm
MD5: 2948b78e82e056b26a177e16b9b8dea5
SHA-256: 431faf073c951fb0dd8e8e81ed408c09ec42701a18531e5f833775a97b6daa37
Size: 20.36 MB
Asianux Server 8 for x86_64
- gdb-8.2-20.1.el8_10.x86_64.rpm
MD5: 528320b979800d0e30317e2f43f16de2
SHA-256: af8ec9be58232108f51205912aad3f04fefc6bca930bc449b31d63bb9bc73a6f
Size: 298.21 kB - gdb-doc-8.2-20.1.el8_10.noarch.rpm
MD5: e86e113a0dc2344e070824412e73feb4
SHA-256: 85f1ad331ad867e574a7503232e1b21b3338fcfaf40b0c3433ec0e734429fe64
Size: 3.94 MB - gdb-gdbserver-8.2-20.1.el8_10.x86_64.rpm
MD5: f5ec4f85bafadd9af7950b6e4cb829c6
SHA-256: 854b90e5381c23ed6bc43290790ca1742b78b829432bf0645fd76c34758542c0
Size: 435.19 kB - gdb-headless-8.2-20.1.el8_10.x86_64.rpm
MD5: 9a56f5005602942577a55921501fee03
SHA-256: 01ede71931e2e968f558813641af9434972b83cc36299cd607c64bf4ead84b1e
Size: 3.67 MB