CVE-2019-9070: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- F5 Traffix Signaling Delivery Controller: from 5.0.0, up to and including 5.1.0
- GNU Binutils: version 2.32 only
- Netapp Element Software Management: any version
Published 2019-02-24. Last modified 2026-06-17.