Impact
The vulnerability resides in the bfd_putl64 function within GNU Binutils’ linker component. A crafted input can trigger a null pointer dereference during relocation processing, leading to a crash of the ld binary. The impact is primarily a local disruption of the build process, potentially causing denial of service for developers or CI systems that rely on the linker. No elevated privileges are directly gained through this rather than remote code execution.
Affected Systems
This flaw affects the GNU Binutils 2.47 release. No other affected versions are listed in the provided data.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity, with an EPSS score not available and absence from the CISA KEV catalog. The attack requires local access and the exploit is publicly available. Because the flaw leads only to a crash, the availability impact is moderate and the likelihood of exploitation is limited to trusted or compromised local users. The lack of a remote reachability vector reduces overall risk compared to higher‑severity vulnerabilities.
OpenCVE Enrichment