Back

MEDIUM

Binutils: binutils: denial of service via crafted elf file

Published Apr 22, 2026

Description

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

Affected products

Remediation

Vendor solution

To mitigate this issue, users should avoid processing untrusted or suspicious ELF files with the `readelf` utility. No specific configuration or operational control is available to prevent this vulnerability without affecting the intended functionality of `readelf`.

Red Hat statement

This Moderate impact vulnerability in the `readelf` utility, part of `binutils`, can lead to a denial of service. An attacker could exploit this by convincing a user to process a specially crafted ELF file, resulting in resource exhaustion or a null pointer dereference. This affects Red Hat Enterprise Linux and Red Hat Developer Toolset where `readelf` is used to examine untrusted ELF binaries.

Red Hat mitigation

To mitigate this issue, users should avoid processing untrusted or suspicious ELF files with the `readelf` utility. No specific configuration or operational control is available to prevent this vulnerability without affecting the intended functionality of `readelf`.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Apr 22, 2026
Updated Sep 1, 2026
Reserved Apr 22, 2026

CISA Vulnrichment

Updated Apr 22, 2026

NVD

Status Modified
Modified Sep 1, 2026

Red Hat

Severity Moderate
Public date Apr 13, 2026
Bugzilla 2460012

ENISA EUVD

Assigner redhat
Published Apr 22, 2026
Updated Sep 1, 2026

GitHub

No data