binutils: Illegal memory access when accessing a zer0-lengthverdef table
Published May 17, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.90%
Description
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
Affected products
- Vendor n/a Product Binutils Defaultn/a
- Version affected at least binutils 2.40StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Binutils | n/a |
|
No data.
Red Hat Enterprise Linux 6
binutils
Out of support scope
Red Hat Enterprise Linux 7
binutils
Fix deferred
Red Hat Enterprise Linux 8
binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-11-binutils
Fix deferred
Red Hat Enterprise Linux 8
gcc-toolset-12-binutils
Fix deferred
Red Hat Enterprise Linux 9
binutils
Fix deferred
Red Hat Enterprise Linux 9
gcc-toolset-12-binutils
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | binutils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-11-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gcc-toolset-12-binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | binutils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gcc-toolset-12-binutils | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this heap-based buffer overflow is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with objdump. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jan 22, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.90% (0.00895) | 58.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.90% (0.00895) | 54.64th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00045) | 10.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00090) | 40.35th | v3 (v2023.03.01) |
| Jun 18, 2024 | 0.08% (0.00078) | 33.91th | v3 (v2023.03.01) |
| May 23, 2024 | 0.07% (0.00070) | 30.07th | v3 (v2023.03.01) |
| Apr 17, 2024 | 0.05% (0.00048) | 16.09th | v3 (v2023.03.01) |
| May 26, 2023 | 0.05% (0.00046) | 14.03th | v3 (v2023.03.01) |
| May 18, 2023 | 0.06% (0.00061) | 23.75th | v3 (v2023.03.01) |
References (6)
- https://access.redhat.com/security/cve/CVE-2023-1972 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2185646 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2023-1972
- https://security.gentoo.org/glsa/202309-15 vendor-advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=30285 Issue TrackingPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1972
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-1972 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2185646 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-1972 | ||
| https://security.gentoo.org/glsa/202309-15 | vendor-advisory | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=30285 | Issue TrackingPatchThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-1972 |
Change history (0)
No recorded changes yet.