GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bison | Aug 22, 2024 | Aug 25, 2020 |
| Debian | — | Upgrade bison | Jul 30, 2024 | Aug 25, 2020 |
| Huawei Euleros 2_0_sp10 | — | Upgrade bison-helpUpgrade bison | Nov 3, 2022 | Aug 25, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Aug 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub