CVE-2026-90830
בינונית 5.3
תיאור (מקור, אנגלית)
A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - CVSS 4.0
-
1.9 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-28/9/2026
- CWE
- CWE-404, CWE-476
מוצרים מושפעים
gnu: binutils
קישורים
- https://sourceware.org/bugzilla/attachment.cgi?id=16884 Third Party AdvisoryIssue Tracking
- https://sourceware.org/bugzilla/show_bug.cgi?id=34452 Third Party AdvisoryIssue Tracking
- https://vuldb.com/cve/CVE-2026-90830 Third Party Advisory
- https://vuldb.com/submit/925229 Third Party Advisory
- https://vuldb.com/vuln/403332 Third Party Advisory
- https://vuldb.com/vuln/403332/cti Permissions Required
- https://www.gnu.org/ Product