CVE-2012-3509: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 3.6% chance of exploitation in the next 30 days.

Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
  • Debian Debian Linux: version 7.0 only
  • GNU Binutils: from 2.22, before 2.24 (fixed in 2.24)
  • GNU Libiberty: affected versions not specified

Published 2012-09-05. Last modified 2026-06-16.