[CVE] zlib (< 1.2.12) memory corruption

Nick Clifton nickc@redhat.com
Fri Apr 8 13:36:52 GMT 2022


Hi Luis,

> There is a CVE [1] for zlib < 1.2.12 (released march 27th).
> 
> GCC currently uses zlib 1.2.11, and binutils-gdb imports the zlib directory from GCC. The recommendation is to get it updated to 1.2.12, which contains the proper fix [2].

I am all for updating the binutils-gdb copy of zlib.  I will wait a couple of
days to see if anyone else has any comments or concerns, but if not, then I
will apply the patches myself.

Cheers
   Nick



More information about the Gcc mailing list