Back

MEDIUM

Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files

Published Apr 22, 2026

Description

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.

Affected products

Remediation

Vendor solution

To mitigate this vulnerability, users should avoid using the `readelf` utility on untrusted or suspicious ELF files. Processing a specially crafted ELF file with `readelf` can lead to a denial of service.

Red Hat statement

Moderate: A denial of service vulnerability in `readelf` can be triggered by processing a crafted ELF file, leading to resource exhaustion or a null pointer dereference. This issue affects Red Hat Enterprise Linux 7, 8, 9, and 10, as well as other Red Hat products that include the binutils package. Exploitation requires a local attacker to entice a user to execute `readelf` on a malicious file.

Red Hat mitigation

To mitigate this vulnerability, users should avoid using the `readelf` utility on untrusted or suspicious ELF files. Processing a specially crafted ELF file with `readelf` can lead to a denial of service.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 22, 2026
Updated Sep 1, 2026
Reserved Apr 22, 2026
CISA Vulnrichment
Updated Apr 23, 2026
NVD
Status Analyzed
Modified Sep 1, 2026
Red Hat
Severity Moderate
Public date Apr 13, 2026
ENISA EUVD
Assigner redhat
Published Apr 22, 2026
Updated Sep 1, 2026
Exploited since n/a
EUVD-2026-24710