#CVE-prep clear

binutils: unsafe symbol-name concatenation via strcpy/strcat into bfd_malloc buffer