Fedora has issued an advisory today (November 10): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/
For Cauldron: CVE-2021-3826 is already fixed. A fix for CVE-2022-27943 is queued in svn and will be pushed when I undate the gcc snapshot to 20221112 on Sunday
RedHat has issued an advisory today (November 15): https://access.redhat.com/errata/RHSA-2022:8415 Has CVE-2021-46195 been fixed already? I haven't seen it mentioned anywhere.
(In reply to David Walser from comment #2) > RedHat has issued an advisory today (November 15): > https://access.redhat.com/errata/RHSA-2022:8415 > > Has CVE-2021-46195 been fixed already? I haven't seen it mentioned anywhere. Yes, fix landed in gcc-12 branch as of: commit f10bec5ffa487ad3033ed5f38cfd0fc7d696deab Author: Nick Clifton <nickc@redhat.com> Date: Mon Jan 31 14:28:42 2022 +0000 libiberty: Fix infinite recursion in rust demangler.
The code affected by CVE-2021-3826, CVE-2022-27943 and CVE-2021-46195 does not exist in Mageia 8 / gcc 10 as it came in with later libiberty code syncs
Status: NEW => RESOLVEDVersion: 8 => CauldronResolution: (none) => FIXED