The vendor explicitly identifies these products or versions as containing the fix.
- capstone-0:5.0.1-7.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-0:5.0.1-7.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-0:5.0.1-7.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-0:5.0.1-7.el10_0.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-0:5.0.1-7.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debuginfo-0:5.0.1-7.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debuginfo-0:5.0.1-7.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debuginfo-0:5.0.1-7.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debuginfo-0:5.0.1-7.el10_0.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debugsource-0:5.0.1-7.el10_0.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debugsource-0:5.0.1-7.el10_0.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- capstone-debugsource-0:5.0.1-7.el10_0.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Summary
- A flaw was found in Capstone, a disassembly framework. A local attacker could exploit a heap buffer overflow vulnerability by providing a specially crafted skipdata callback. This flaw occurs because the skipdata length is not properly bounds-checked, which may allow an attacker to write beyond allocated memory, potentially leading to a denial of service (DoS) or arbitrary code execution.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
