CVE-2016-9276: Libdwarf Project Libdwarf

High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.

The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

Affected products

  • Libdwarf Project Libdwarf: from 1999-12-14, before 2016-11-24 (fixed in 2016-11-24)

Published 2017-03-23. Last modified 2026-06-17.