CVE-2016-2226: GNU Libiberty

High severity, CVSS 7.8. EPSS: 7.2% chance of exploitation in the next 30 days.

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

Affected products

  • GNU Libiberty: any version

Published 2017-02-24. Last modified 2026-06-17.