Description
A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Local) via null pointer dereference
Action: Patch
AI Analysis

Impact

The vulnerability is a null pointer dereference in the elf_orphan_compatible function within the ELF Orphan Section Handler of GNU Binutils. When an attacker constructs a malicious ELF file that triggers this function, the program attempts to use a null pointer, causing a crash. The flaw does not provide any remote code execution or privilege escalation capabilities.

Affected Systems

Affected software is GNU Binutils 2.47, released by the GNU project. Earlier releases are not explicitly mentioned, but the vulnerable code path exists in 2.47 and may be present in the same series. The product is Binutils, a collection of binary utilities distributed by GNU.

Risk and Exploitability

The CVSS score for this issue is 4.8, indicating a moderate severity. The EPSS score is <1%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers must initiate the exploit locally and the public exploit code is available; therefore the risk is primarily that a local attacker can cause service interruptions, but the likelihood of widespread exploitation remains low due to the local nature of the attack vector.

Generated by OpenCVE AI on September 17, 2026 at 19:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GNU Binutils to a fixed release (e.g., 2.48 or later) once the vendor publishes a patch.
  • If an immediate upgrade is not possible, restrict execution of binaries that use the vulnerable ELF Orphan Section Handler to authorized users only, verifying that only trusted code runs with elevated privileges.
  • Configure system monitoring or logging to alert administrators when segmentation fault or abort signals occur from binutils binaries, indicating a potential exploitation attempt.

Generated by OpenCVE AI on September 17, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Title GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:55:03.840Z

Reserved: 2026-09-13T19:21:23.987Z

Link: CVE-2026-90828

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:06.454Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T22:16:58.690

Modified: 2026-09-21T17:49:28.070

Link: CVE-2026-90828

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T22:00:20Z

Links: CVE-2026-90828 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference