PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-4492 Gnu CVE debrief

CVE-2016-4492 describes a buffer overflow in libiberty's do_type function in cplus-dem.c. The issue is tracked as CWE-119 and, per NVD, can lead to a crash/segmentation fault and denial of service in affected GNU libiberty environments. The official NVD CVSS vector rates it as AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H, so the recorded impact is availability-only and requires local, high-privilege conditions.

Vendor
Gnu
Product
Libiberty
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-24
Original CVE updated
2026-05-13
Advisory published
2017-02-24
Advisory updated
2026-05-13

Who should care

Administrators, maintainers, and build/packaging teams responsible for GNU libiberty or GCC-related toolchains should review this issue, especially where demangling or binary-processing code may be invoked on untrusted or malformed inputs.

Technical summary

NVD identifies the vulnerable component as cpe:2.3:a:gnu:libiberty:* and classifies the weakness as CWE-119. The affected code path is do_type in cplus-dem.c. The issue is described as a buffer overflow that can cause a segmentation fault and crash; the NVD CVSS vector indicates the practical security consequence is denial of service rather than confidentiality or integrity impact.

Defensive priority

Medium priority for affected build and toolchain environments: the severity is moderate, but the potential outcome is an availability-impacting crash in a core library component.

Recommended defensive actions

  • Check whether your environment uses GNU libiberty or packages that embed it, including GCC-related toolchain components.
  • Apply the vendor patch or update referenced in the GCC patch mailing list and related bug tracker entry.
  • Backport the fix into any supported downstream packages that ship libiberty if an upstream update is not immediately available.
  • Test affected binaries and toolchain workflows with malformed or unexpected inputs to confirm the crash condition is eliminated after remediation.
  • Monitor for abnormal process termination or segmentation faults in components that invoke cplus-dem.c functionality.

Evidence notes

Primary evidence comes from the NVD record for CVE-2016-4492, which lists the weakness as CWE-119 and the CVSS v3 vector as CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. The NVD metadata also identifies the vulnerable CPE as gnu:libiberty and includes references to the Openwall oss-security thread, GCC bug 70926, and the GCC patches mailing list, all dated in the supplied corpus. The CVE record was published on 2017-02-24 and later modified on 2026-05-13.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-4492 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-4492

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-4492 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4492

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.