Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90804

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 4.8
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

EPSS

Процентиль: 2%
0.00117
Низкий

4.8 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
redhat
3 дня назад

A flaw was found in GNU Binutils. A buffer overflow vulnerability exists in the _bfd_elf_write_section_eh_frame function, part of the Eh Frame Section Handler. A local attacker can exploit this by providing specially crafted input that manipulates arguments such as cie_length or fde_length. This manipulation can lead to a denial of service.

CVSS3: 4.8
debian
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this is ...

CVSS3: 4.8
github
2 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

EPSS

Процентиль: 2%
0.00117
Низкий

4.8 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119