VendorsGNUbinutilsall versions
Vulnerabilities

GNU Binutils

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

288CVEs
CVE-2023-25585
Field `file_table` of `struct module *module` is uninitialized
Published 2023-09-14 · Modified
5.5EPSS 0.004
CVE-2023-25588
Field `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab`
Published 2023-09-14 · Modified
5.5EPSS 0.004
CVE-2023-25586
Local variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitialized
Published 2023-09-14 · Modified
5.5EPSS 0.003
CVE-2022-35206
Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2022-38533
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
Published 2022-08-25 · Modified
5.5EPSS 0.003
CVE-2020-21490
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2020-19724
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2025-3198
GNU Binutils objdump bucomm.c display_info memory leak
Published 2025-04-04 · Modified
5.5EPSS 0.003
CVE-2025-11839
GNU Binutils prdbg.c tg_tag_type return value
Published 2025-10-16 · Modified
5.5EPSS 0.003
CVE-2025-11840
GNU Binutils ldmisc.c vfinfo out-of-bounds
Published 2025-10-16 · Modified
5.5EPSS 0.003
CVE-2025-69651
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.
Published 2026-03-06 · Modified
5.5EPSS 0.002
CVE-2025-11495
GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow
Published 2025-10-08 · Modified
5.5EPSS 0.002
CVE-2025-8224
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Published 2025-07-27 · Modified
5.5EPSS 0.002
CVE-2025-11413
GNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds
Published 2025-10-07 · Modified
5.5EPSS 0.002
CVE-2025-11494
GNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds
Published 2025-10-08 · Modified
5.5EPSS 0.002
CVE-2025-11412
GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds
Published 2025-10-07 · Modified
5.5EPSS 0.002
CVE-2025-11414
GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds
Published 2025-10-07 · Modified
5.5EPSS 0.002
CVE-2025-11081
GNU Binutils objdump.c dump_dwarf_section out-of-bounds
Published 2025-09-27 · Analyzed
5.5EPSS 0.002
CVE-2025-69645
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.
Published 2026-03-06 · Analyzed
5.5EPSS 0.002
CVE-2025-69646
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.
Published 2026-03-06 · Analyzed
5.5EPSS 0.002
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2025-1147
GNU Binutils nm nm.c internal_strlen buffer overflow
Published 2025-02-10 · Modified
5.3EPSS 0.007
CVE-2026-90829
GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference
Published 2026-09-14 · Analyzed
5.3EPSS 0.002
CVE-2026-90831
GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruption
Published 2026-09-14 · Analyzed
5.3EPSS 0.002
CVE-2026-90830
GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference
Published 2026-09-14 · Analyzed
5.3EPSS 0.002
CVE-2025-1181
GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec memory corruption
Published 2025-02-11 · Analyzed
5.1EPSS 0.007
CVE-2025-1176
GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
Published 2025-02-11 · Modified
5.1EPSS 0.007
CVE-2025-1182
GNU Binutils ld elflink.c bfd_elf_reloc_symbol_deleted_p memory corruption
Published 2025-02-11 · Analyzed
5.1EPSS 0.006
CVE-2014-8738
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
Published 2015-01-15 · Modified
5.0EPSS 0.052
CVE-2014-8484
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
Published 2014-12-09 · Modified
5.0EPSS 0.051
CVE-2012-3509
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
Published 2012-09-05 · Modified
5.0EPSS 0.036
CVE-2026-6845
Binutils: binutils: denial of service via crafted elf file
Published 2026-04-22 · Modified
5.0EPSS 0.001
CVE-2025-69644
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.
Published 2026-03-06 · Analyzed
5.0EPSS 0.001
CVE-2026-90802
GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference
Published 2026-09-14 · Analyzed
4.4EPSS 0.002
CVE-2020-35448
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.
Published 2020-12-27 · Modified
4.3EPSS 0.012
CVE-2025-1152
GNU Binutils ld xstrdup.c xstrdup memory leak
Published 2025-02-10 · Analyzed
3.7EPSS 0.006
CVE-2014-8737
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
Published 2014-12-09 · Modified
3.6EPSS 0.010
CVE-2025-8225
GNU Binutils DWARF Section dwarf.c process_debug_info memory leak
Published 2025-07-27 · Analyzed
3.3EPSS 0.002
CVE-2026-91782
GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereference
Published 2026-09-15 · Analyzed
3.3EPSS 0.002
CVE-2026-91781
GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference
Published 2026-09-15 · Analyzed
3.3EPSS 0.002
← Prev7 / 8Next →