Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6845

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in binutils, specifically within the readelf utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

Отчет

This Moderate impact vulnerability in the readelf utility, part of binutils, can lead to a denial of service. An attacker could exploit this by convincing a user to process a specially crafted ELF file, resulting in resource exhaustion or a null pointer dereference. This affects Red Hat Enterprise Linux and Red Hat Developer Toolset where readelf is used to examine untrusted ELF binaries.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted or suspicious ELF files with the readelf utility. No specific configuration or operational control is available to prevent this vulnerability without affecting the intended functionality of readelf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10binutilsFix deferred
Red Hat Enterprise Linux 10gcc-toolset-15-binutilsFix deferred
Red Hat Enterprise Linux 10gdbFix deferred
Red Hat Enterprise Linux 10mingw-binutilsFix deferred
Red Hat Enterprise Linux 6binutilsFix deferred
Red Hat Enterprise Linux 7binutilsFix deferred
Red Hat Enterprise Linux 7gdbFix deferred
Red Hat Enterprise Linux 8binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-14-binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-14-gdbFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2460012binutils: Binutils: Denial of Service via crafted ELF file

EPSS

Процентиль: 4%
0.00147
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
3 месяца назад

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

CVSS3: 5
nvd
3 месяца назад

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

msrc
3 месяца назад

Binutils: binutils: denial of service via crafted elf file

CVSS3: 5
debian
3 месяца назад

A flaw was found in binutils, specifically within the `readelf` utilit ...

CVSS3: 5
github
3 месяца назад

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

EPSS

Процентиль: 4%
0.00147
Низкий

5 Medium

CVSS3