Impact
A buffer overflow occurs in the elf_x86_64_relocate_section routine when the relocatable offset is manipulated. The vulnerability is limited to local exploitation; an attacker must execute code on the same machine as the vulnerable ld binary. The overflow could overwrite adjacent memory and potentially allow the attacker to control the program execution flow, leading to arbitrary code execution within the context of the ld process.
Affected Systems
The flaw is present in GNU Binutils version 2.47. The component impacted is the ld linker, specifically the elf64‑x86‑64.c source file. Users of this version, or those who build applications with this ld binary without applying the available patch, are affected. Upgrading to 2.48 removes the vulnerability.
Risk and Exploitability
The CVSS score of 4.8 categorises it as a low‑severity flaw with local impact. EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not known. Nevertheless, any local user running ld with malicious input could trigger the overflow and possibly execute code as that user. The attack vector is explicitly described as local, and the patch has been published and can be applied directly.
OpenCVE Enrichment