docorenote in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "12.2"
}
],
"vendor_product": "apple:iphone_os"
},
{
"cpes": [
"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "10.14.4"
}
],
"vendor_product": "apple:mac_os_x"
},
{
"cpes": [
"cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "12.2"
}
],
"vendor_product": "apple:tvos"
},
{
"cpes": [
"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "5.2"
}
],
"vendor_product": "apple:watchos"
},
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "16.04"
},
{
"last_affected": "16.04"
},
{
"introduced": "18.04"
},
{
"last_affected": "18.04"
},
{
"introduced": "18.10"
},
{
"last_affected": "18.10"
}
],
"vendor_product": "canonical:ubuntu_linux"
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "15.0"
},
{
"last_affected": "15.0"
},
{
"introduced": "42.3"
},
{
"last_affected": "42.3"
}
],
"vendor_product": "opensuse:leap"
}
]
}"2026-07-08T19:51:40Z"
[
{
"signature_type": "Function",
"target": {
"file": "src/readelf.c",
"function": "do_core_note"
},
"deprecated": false,
"source": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f",
"id": "CVE-2019-8906-62c7b43b",
"signature_version": "v1",
"digest": {
"function_hash": "50134300944515749486679894215678025456",
"length": 3326.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/readelf.c"
},
"deprecated": false,
"source": "https://github.com/file/file/commit/2858eaf99f6cc5aae129bcbf1e24ad160240185f",
"id": "CVE-2019-8906-f339bc00",
"signature_version": "v1",
"digest": {
"line_hashes": [
"333164384304000014939969775433987025057",
"305247237807722948317776446743530876769",
"251035260985686906017783394955669487551",
"334815268474935935102152633450803886526",
"118413130556114706998516904846100232",
"317474704739742838936164869212100976187",
"100801867789909417053187722427126381463"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-8906.json"