docorenote in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
{ "vanir_signatures": [ { "digest": { "function_hash": "50134300944515749486679894215678025456", "length": 3326.0 }, "signature_type": "Function", "source": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f", "target": { "file": "src/readelf.c", "function": "do_core_note" }, "signature_version": "v1", "deprecated": false, "id": "CVE-2019-8906-62c7b43b" }, { "digest": { "threshold": 0.9, "line_hashes": [ "333164384304000014939969775433987025057", "305247237807722948317776446743530876769", "251035260985686906017783394955669487551", "334815268474935935102152633450803886526", "118413130556114706998516904846100232", "317474704739742838936164869212100976187", "100801867789909417053187722427126381463" ] }, "signature_type": "Line", "source": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f", "target": { "file": "src/readelf.c" }, "signature_version": "v1", "deprecated": false, "id": "CVE-2019-8906-f339bc00" } ] }