Back

HIGH

binutils: double free in readelf via crafted ELF binary with malformed relocation data

Published Mar 6, 2026

Description

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.

Affected products

Remediation

Red Hat statement

This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this double free vulnerability is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with readelf. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

Red Hat mitigation

To mitigate this vulnerability, do not process untrusted, unverified or externally supplied ELF binaries with the readelf program.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 6, 2026
Updated Mar 19, 2026
Reserved Jan 9, 2026
CISA Vulnrichment
Updated Mar 12, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 6, 2026
ENISA EUVD
Assigner mitre
Published Mar 6, 2026
Updated Mar 19, 2026
Exploited since n/a
EUVD-2025-208346