Description
A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via null pointer dereference
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the bfd_putl64 function within GNU Binutils’ linker component. A crafted input can trigger a null pointer dereference during relocation processing, leading to a crash of the ld binary. The impact is primarily a local disruption of the build process, potentially causing denial of service for developers or CI systems that rely on the linker. No elevated privileges are directly gained through this rather than remote code execution.

Affected Systems

This flaw affects the GNU Binutils 2.47 release. No other affected versions are listed in the provided data.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium severity, with an EPSS score not available and absence from the CISA KEV catalog. The attack requires local access and the exploit is publicly available. Because the flaw leads only to a crash, the availability impact is moderate and the likelihood of exploitation is limited to trusted or compromised local users. The lack of a remote reachability vector reduces overall risk compared to higher‑severity vulnerabilities.

Generated by OpenCVE AI on September 15, 2026 at 13:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Confirm that the installed Binutils version is not 2.47; if a patched or newer version is available from the vendor, install it as early as possible.
  • If an update is not available, restrict execution of the ld linker to trusted inputs only, and consider running it inside a sandbox or isolated environment to contain a potential crash.
  • Continuously monitor the vendor’s bug tracker, advisories, and CVE feeds for an official patch; apply the fix immediately when released.

Generated by OpenCVE AI on September 15, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Title GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 3.2, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:17:58.409Z

Reserved: 2026-09-13T15:33:42.169Z

Link: CVE-2026-90802

cve-icon Vulnrichment

Updated: 2026-09-16T15:17:51.747Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T17:17:56.800

Modified: 2026-09-18T14:42:16.407

Link: CVE-2026-90802

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T16:30:18Z

Links: CVE-2026-90802 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:30:13Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference