CVE-2016-9558 describes a negation overflow vulnerability in libdwarf, specifically affecting libdwarf/dwarf_leb.c and dwarfdump/print_frames.c in versions prior to 20161124. This critical vulnerability, rated 9.8 CVSS, allows remote attackers to achieve high impact on confidentiality, integrity, and availability through a crafted bit pattern in a signed LEB number. Despite its severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and community discussion is minimal, with no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1999-12-14, < 2016-11-24CPE matchmatch criteria | cpe:2.3:a:libdwarf_project:libdwarf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.