upx is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the segmentation fault in the PackLinuxElf64::invert_pt_dynamic()
function of p_lx_elf.cpp
which leads to invalid memory address access, allowing an attacker to cause an application crash
bugzilla.redhat.com/show_bug.cgi?id=2160382
github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860
github.com/upx/upx/issues/631
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ/
lists.fedoraproject.org/archives/list/[email protected]/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI/
lists.fedoraproject.org/archives/list/[email protected]/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ/
secdb.alpinelinux.org/edge/community.yaml
secdb.alpinelinux.org/v3.17/community.yaml