CyberRota Analysis
AI-GeneratedThe vulnerability affects GDB's STABS debug format parser, specifically in the `read_member_functions()` function, which improperly handles destructor entries in C++ class member functions. This flaw can lead to an out-of-bounds write, allowing an attacker to execute arbitrary commands within the GDB process by crafting a malicious ELF binary. Organizations using GDB for debugging should prioritize addressing this vulnerability to mitigate the risk of exploitation during symbol-inspection operations.
Original NVD Description
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.