OESA-2023-1001

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1001
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1001.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1001
Upstream
Published
2023-01-03T11:04:44Z
Modified
2025-08-12T05:15:51.623150Z
Summary
patchelf security update
Details

PatchELF is a simple utility for modifying an existing ELF executable or library. It can change the dynamic loader ("ELF interpreter") of an executable and change the RPATH of an executable or library.

Security Fix(es):

Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc.(CVE-2022-44940)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:22.03-LTS / patchelf

Package

Name
patchelf
Purl
pkg:rpm/openEuler/patchelf&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.16.0-1.oe2203sp1

Ecosystem specific

{
    "src": [
        "patchelf-0.16.0-1.oe2203.src.rpm",
        "patchelf-0.16.0-1.oe2203sp1.src.rpm"
    ],
    "aarch64": [
        "patchelf-0.16.0-1.oe2203.aarch64.rpm",
        "patchelf-debuginfo-0.16.0-1.oe2203.aarch64.rpm",
        "patchelf-debugsource-0.16.0-1.oe2203.aarch64.rpm",
        "patchelf-0.16.0-1.oe2203sp1.aarch64.rpm",
        "patchelf-debuginfo-0.16.0-1.oe2203sp1.aarch64.rpm",
        "patchelf-debugsource-0.16.0-1.oe2203sp1.aarch64.rpm"
    ],
    "x86_64": [
        "patchelf-debuginfo-0.16.0-1.oe2203.x86_64.rpm",
        "patchelf-debugsource-0.16.0-1.oe2203.x86_64.rpm",
        "patchelf-0.16.0-1.oe2203.x86_64.rpm",
        "patchelf-debuginfo-0.16.0-1.oe2203sp1.x86_64.rpm",
        "patchelf-debugsource-0.16.0-1.oe2203sp1.x86_64.rpm",
        "patchelf-0.16.0-1.oe2203sp1.x86_64.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / patchelf

Package

Name
patchelf
Purl
pkg:rpm/openEuler/patchelf&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.16.0-1.oe2203sp1

Ecosystem specific

{
    "src": [
        "patchelf-0.16.0-1.oe2203sp1.src.rpm"
    ],
    "aarch64": [
        "patchelf-0.16.0-1.oe2203sp1.aarch64.rpm",
        "patchelf-debuginfo-0.16.0-1.oe2203sp1.aarch64.rpm",
        "patchelf-debugsource-0.16.0-1.oe2203sp1.aarch64.rpm"
    ],
    "x86_64": [
        "patchelf-debuginfo-0.16.0-1.oe2203sp1.x86_64.rpm",
        "patchelf-debugsource-0.16.0-1.oe2203sp1.x86_64.rpm",
        "patchelf-0.16.0-1.oe2203sp1.x86_64.rpm"
    ]
}