libdwarf: heap-based buffer overflow in _dwarf_get_size_of_val (dwarf_util.c)

Description: libdwarf is a library to consume and produce DWARF debug information. A fuzzing revealed an out bounds read, The complete ASan output: # dwarfdump $FILE ==22886==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x61300000de1c at pc 0x000000462c7c bp 0x7ffe80a3d230 sp 0x7ffe80a3c9e0 READ … Continue reading libdwarf: heap-based buffer overflow in _dwarf_get_size_of_val (dwarf_util.c)