Back

MEDIUM

binutils: NULL pointer dereference in elf_link_input_bfd in elflink.c

Published Oct 23, 2018

Description

An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.

Affected products

Remediation

Red Hat statement

Red Hat has determined this flaw to be of low impact as successful exploitation results in a crash (denial of service) of the application utilizing the binutils library and does not impact system-wide stability or lead to arbitrary code execution or memory corruption.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2018
Updated Aug 5, 2024
Reserved Oct 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 21, 2018