{"id":"AZL-98547","summary":"CVE-2026-13732 affecting package crash 9.0.0-3","details":"A flaw was found in GDB's STABS debug format parser. The\nread_member_functions() function in gdb/stabsread.c contains a linked\nlist removal bug in the code that separates destructor and non-destructor\nmember functions of C++ classes. The bug causes the destructor entries to\nremain in the main function list while the list length counter is\ndecremented, resulting in an out-of-bounds write when the function list\nis copied to its final allocated array. An attacker can craft an ELF\nbinary with malicious .stab and .stabstr sections that triggers this\nout-of-bounds write when a user opens the file in GDB and performs any\nsymbol-inspection operation such as setting a breakpoint. The inferior\nprocess does not need to be executed. Under controlled conditions, this\nwas demonstrated to achieve execution of arbitrary commands within the\nGDB process.","modified":"2026-09-03T14:17:00.151671598Z","published":"2026-08-31T20:17:02Z","upstream":["CVE-2026-13732"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13732"}],"affected":[{"package":{"name":"crash","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/crash"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"9.0.0-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98547.json"}}],"schema_version":"1.9.0"}