← Vulnerability feed

Vulnerability record · CVE-2016-6131 · published 7 February 2017

CVE-2016-6131: Gnu libiberty improper input validation vulnerability

Gnu · Libiberty

The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.

7.5 CVSS 3.0 High EPSS 4.6% · top 8.6% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
4.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-6131 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2016-2226Gnu libiberty memory buffer overflow vulnerabilityInteger overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executabl…EPSS 7.3%5.5CVE-2016-4487Gnu libiberty use after free vulnerabilityUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…EPSS 1.7%5.5CVE-2016-4488Gnu libiberty use after free vulnerabilityUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, r…EPSS 1.7%5.5CVE-2016-4489Gnu libiberty integer overflow vulnerabilityInteger overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a c…EPSS 1.7%5.5CVE-2016-4490Gnu libiberty integer overflow vulnerabilityInteger overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted bina…EPSS 1.8%5.5CVE-2016-4491Gnu libiberty memory buffer overflow vulnerabilityThe d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a cra…EPSS 1.8%5.5CVE-2016-4493Gnu libiberty out-of-bounds read vulnerabilityThe demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of serv…EPSS 1.6%5.0CVE-2012-3509Gnu binutils vulnerabilityMultiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as …EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2016-6131), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.