Back

MEDIUM

binutils: Null Pointer Dereference in scan_unit_for_symbols could result in DoS

Published Dec 9, 2020

Description

A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file.

Affected products

Remediation

Red Hat statement

binutils as shipped in Red Hat Developer Toolsets 9 and 10, Red Hat Enterprise Linux 8 BaseOS and GCC Toolsets 9 and 10, are all not affected by this flaw as it was introduced in a newer version of binutils code than shipped for BaseOS and the 9 toolsets, and already patched in the versions shipped with 10 toolsets.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 9, 2020
Updated Aug 4, 2024
Reserved Aug 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 10, 2020
ENISA EUVD
Assigner mitre
Published Dec 9, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-8554