Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90804

Опубликовано: 14 сент. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

A flaw was found in GNU Binutils. A buffer overflow vulnerability exists in the _bfd_elf_write_section_eh_frame function, part of the Eh Frame Section Handler. A local attacker can exploit this by providing specially crafted input that manipulates arguments such as cie_length or fde_length. This manipulation can lead to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened ImagesbinutilsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2533209binutils: GNU Binutils: Buffer overflow in Eh Frame Section Handler can lead to denial of service

EPSS

Процентиль: 2%
0.00117
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
nvd
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
debian
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this is ...

CVSS3: 4.8
github
2 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

EPSS

Процентиль: 2%
0.00117
Низкий

4.8 Medium

CVSS3

Уязвимость CVE-2026-90804