Impact
The vulnerability is a null pointer dereference in the elf_orphan_compatible function within the ELF Orphan Section Handler of GNU Binutils. When an attacker constructs a malicious ELF file that triggers this function, the program attempts to use a null pointer, causing a crash. The flaw does not provide any remote code execution or privilege escalation capabilities.
Affected Systems
Affected software is GNU Binutils 2.47, released by the GNU project. Earlier releases are not explicitly mentioned, but the vulnerable code path exists in 2.47 and may be present in the same series. The product is Binutils, a collection of binary utilities distributed by GNU.
Risk and Exploitability
The CVSS score for this issue is 4.8, indicating a moderate severity. The EPSS score is <1%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers must initiate the exploit locally and the public exploit code is available; therefore the risk is primarily that a local attacker can cause service interruptions, but the likelihood of widespread exploitation remains low due to the local nature of the attack vector.
OpenCVE Enrichment