libdwarf.so is vulnerable to denial of service. The vulnerability exists in _dwarf_exec_frame_instr
function in dwarf_frame.c
due to a double-free vulnerability which allows an attacker to cause an application crash via a malicious input.
github.com/advisories/GHSA-q3xx-pg8c-jqh6
github.com/davea42/libdwarf-code/commit/428235e3d132fb62faf7732735fdbb034d6264b4
github.com/davea42/libdwarf-code/commit/60303eb80ecc7747bf29776d545e2a5c5a76f6f8
github.com/davea42/libdwarf-code/issues/132
lists.fedoraproject.org/archives/list/[email protected]/message/IKUE4XT62AEZ3H5D6GMREYOSCMMRFXBH/