Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-90804

Опубликовано: 14 сент. 2026
Источник: debian

Описание

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
binutilsunfixedpackage

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=34445

  • binutils not covered by security support

Связанные уязвимости

CVSS3: 4.8
ubuntu
2 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
redhat
3 дня назад

A flaw was found in GNU Binutils. A buffer overflow vulnerability exists in the _bfd_elf_write_section_eh_frame function, part of the Eh Frame Section Handler. A local attacker can exploit this by providing specially crafted input that manipulates arguments such as cie_length or fde_length. This manipulation can lead to a denial of service.

CVSS3: 4.8
nvd
2 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
github
2 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.