CVE-2018-12699: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.

Affected products

  • Canonical Ubuntu Linux: version 16.04.4 only
  • GNU Binutils: version 2.30 only

Published 2018-06-23. Last modified 2026-06-17.