Impact
A buffer overflow occurs in the cache_bwrite() function of GNU Binutils ld when the nbytes parameter is manipulated. The overflow can corrupt memory, potentially allowing an attacker to overwrite return addresses or other control data, which may lead to remote code execution or execution of arbitrary code. The flaw is classified as CWE-119 and CWE-120 and carries a CVSS score of 4.8, indicating moderate severity. The attack is local in nature but the public release of the exploit means that compromised systems could be used to facilitate further attacks.
Affected Systems
The vulnerability affects GNU Binutils version 2.47 across all platforms supported by the library, as identified by the CPE cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* and the vendor product listing GNU:Binutils. No specific sub‑versions beyond 2.47 are listed; therefore earlier releases are assumed unaffected, but verification is recommended.
Risk and Exploitability
The CVSS score of 4.8 shows that the vulnerability is moderate; however, the exploit is publicly available which increases the risk of real‑world usage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but its local nature and public release raise concern for environments that handle untrusted ELF files. The attack path involves an adversary with local access injecting a malformed ELF file that triggers the cache_bwrite overflow while the linker is invoked with a malicious --gc-sections -w parameter. Successful exploitation can lead to arbitrary code execution on the vulnerable system.
OpenCVE Enrichment