MEDIUM

CVE-2026-90804

Gnu Binutils 2026-09-14 CVSS v3.1
CVSS
6.1

Description

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error
CWE-120 Classic Buffer Overflow

EPSS Score

0.14%
Probability of exploitation in next 30 days
3.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE