Description
A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-14
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is a buffer overflow in the _bfd_elf_write_section_eh_frame function within the Eh Frame Section Handler of GNU Binutils 2.47. Manipulating the cie_length, fde_length, augmentation_data_size, or write_offset arguments can overflow an internal buffer, potentially allowing an attacker to execute arbitrary code with the privileges of the user running the binutils toolchain. This vulnerability is a classic stack-based buffer overflow (CWE‑119) and also a write‑what‑where condition (CWE‑120). Additionally, the exploit leverages negative size handling, leading to an out‑of‑bounds write (CWE‑805). The impact is limited to the host machine because the exploit requires local access and the affected code executes during the creation or modification of ELF binaries.

Affected Systems

The vulnerability affects the GNU Binutils package, specifically version 2.47, which implements the _bfd_elf_write_section_eh_frame function. No other versions or vendors are explicitly listed as affected in the CVE data.

Risk and Exploitability

The CVSS score of 2.4 indicates a low overall severity, and the EPSS score is less than 1 percent, implying a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw requires local execution and directly targets a build tool, so it is best mitigated by updating or patching Binutils. If the fix is not yet released, the exploit remains public and could be used by local attackers with sufficient privileges.

Generated by OpenCVE AI on September 20, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest GNU Binutils release that contains the fix for the _bfd_elf_write_section_eh_frame buffer overflow.
  • If an updated binary is unavailable, rebuild the filesystem or binaries with a patched source that removes the vulnerable code path or adds bounds checking for cie_length, fde_length, augmentation_data_size, and write_offset.
  • Configure the compiler with stack protection and address space layout randomization when building Binutils to reduce the impact of any residual buffer overflow.

Generated by OpenCVE AI on September 20, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Title GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflow
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-119
CWE-120
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:56:28.768Z

Reserved: 2026-09-13T15:33:49.112Z

Link: CVE-2026-90804

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:10.341Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T17:17:57.163

Modified: 2026-09-18T14:42:39.483

Link: CVE-2026-90804

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T17:00:17Z

Links: CVE-2026-90804 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-805

    Buffer Access with Incorrect Length Value