QID 352841

Date Published: 2021-09-20

QID 352841: Amazon Linux Security Advisory for gcc10-binutils: ALAS2-2021-1702

An issue was discovered in the binary file descriptor (bfd) library (aka libbfd), as distributed in gnu binutils 2.35.1.
A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c. (
( CVE-2020-35448) a flaw was found in binutils' readelf program.
An attacker who is able to convince a victim using readelf to read a crafted file, could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker.
The highest impact of this flaw is to confidentiality, integrity, and availability. (
( CVE-2021-20294) there's a flaw in the bfd library of binutils.
An attacker who supplies a crafted file to an application linked with bfd, and using the dwarf functionality, could cause an impact to system availability by way of excessive memory consumption. (
( CVE-2021-3487)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2-2021-1702 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352841

    Software Advisories
    Advisory ID Software Component Link
    ALAS2-2021-1702 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1702.html