« Back to list

GNU

GNU Binutils: vulnerabilities and CVEs

GNU Binutils has 291 published vulnerabilities, 42 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs291
Last 12 months42
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-91782Low (1.9)0.18%—Sep 15, 2026
A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation…
CVE-2026-91781Low (1.9)0.18%—Sep 15, 2026
A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to…
CVE-2026-91780Low (1.9)0.17%—Sep 15, 2026
A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be…
CVE-2026-91779Low (1.9)0.17%—Sep 15, 2026
A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in…
CVE-2026-90831Low (1.9)0.17%—Sep 14, 2026
A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory…
CVE-2026-90830Low (1.9)0.17%—Sep 14, 2026
A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer…
CVE-2026-90829Low (1.9)0.17%—Sep 14, 2026
A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null…
CVE-2026-90828Low (1.9)0.19%—Sep 14, 2026
A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation…
CVE-2026-90804Low (0.9)0.20%—Sep 14, 2026
A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a…
CVE-2026-90803Low (1.9)0.20%—Sep 14, 2026
A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the…
CVE-2026-90802Low (1.9)0.18%—Sep 14, 2026
A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access.…
CVE-2026-90801Low (1.9)0.21%—Sep 14, 2026
A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The…
CVE-2026-18220High (7.8)0.19%—Jul 29, 2026
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails…
CVE-2026-15003Medium (5.6)0.15%—Jul 27, 2026
A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File…
CVE-2026-6846High (7.8)0.20%—Apr 22, 2026
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user…
CVE-2026-6845Medium (5)0.14%—Apr 22, 2026
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable…
CVE-2026-6844Medium (5.5)0.15%—Apr 22, 2026
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file.…
CVE-2026-4647Medium (6.1)0.17%—Mar 23, 2026
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a…
CVE-2026-3442High (7.1)0.19%—Mar 16, 2026
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process…
CVE-2026-3441High (7.1)0.19%—Mar 16, 2026
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to…
CVE-2025-69648Medium (6.2)0.18%—Mar 9, 2026
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly…
CVE-2025-69647Medium (6.2)0.15%—Mar 9, 2026
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly…
CVE-2025-69652Medium (6.2)0.17%—Mar 6, 2026
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in…
CVE-2025-69650High (7.5)0.50%—Mar 6, 2026
GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without…
CVE-2025-69649High (7.5)0.26%—Mar 6, 2026
GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be…
CVE-2025-69651Medium (5.5)0.24%—Mar 6, 2026
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to…
CVE-2025-69646Medium (5.5)0.15%—Mar 6, 2026
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to…
CVE-2025-69645Medium (5.5)0.17%—Mar 6, 2026
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid…
CVE-2025-69644Medium (5)0.13%—Mar 6, 2026
An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location…
CVE-2025-66866High (7.5)0.31%—Dec 29, 2025
An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Other products by GNU