PatchSiren cyber security CVE debrief
CVE-2016-4492 Gnu CVE debrief
CVE-2016-4492 describes a buffer overflow in libiberty's do_type function in cplus-dem.c. The issue is tracked as CWE-119 and, per NVD, can lead to a crash/segmentation fault and denial of service in affected GNU libiberty environments. The official NVD CVSS vector rates it as AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H, so the recorded impact is availability-only and requires local, high-privilege conditions.
- Vendor
- Gnu
- Product
- Libiberty
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-24
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-24
- Advisory updated
- 2026-05-13
Who should care
Administrators, maintainers, and build/packaging teams responsible for GNU libiberty or GCC-related toolchains should review this issue, especially where demangling or binary-processing code may be invoked on untrusted or malformed inputs.
Technical summary
NVD identifies the vulnerable component as cpe:2.3:a:gnu:libiberty:* and classifies the weakness as CWE-119. The affected code path is do_type in cplus-dem.c. The issue is described as a buffer overflow that can cause a segmentation fault and crash; the NVD CVSS vector indicates the practical security consequence is denial of service rather than confidentiality or integrity impact.
Defensive priority
Medium priority for affected build and toolchain environments: the severity is moderate, but the potential outcome is an availability-impacting crash in a core library component.
Recommended defensive actions
- Check whether your environment uses GNU libiberty or packages that embed it, including GCC-related toolchain components.
- Apply the vendor patch or update referenced in the GCC patch mailing list and related bug tracker entry.
- Backport the fix into any supported downstream packages that ship libiberty if an upstream update is not immediately available.
- Test affected binaries and toolchain workflows with malformed or unexpected inputs to confirm the crash condition is eliminated after remediation.
- Monitor for abnormal process termination or segmentation faults in components that invoke cplus-dem.c functionality.
Evidence notes
Primary evidence comes from the NVD record for CVE-2016-4492, which lists the weakness as CWE-119 and the CVSS v3 vector as CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H. The NVD metadata also identifies the vulnerable CPE as gnu:libiberty and includes references to the Openwall oss-security thread, GCC bug 70926, and the GCC patches mailing list, all dated in the supplied corpus. The CVE record was published on 2017-02-24 and later modified on 2026-05-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-4492 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-4492
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-4492 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4492
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gcc.gnu.org/ml/gcc-patches/2016-05/msg00223.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.