Impact
A weakness was identified in GNU Binutils 2.47. The flaw resides in the function bfd_elf_set_group_contents used to parse the SHT_GROUP section of ELF files. When a maliciously crafted ELF file is processed, the function dereferences a null pointer, causing the vulnerable binary to crash. The issue is triggered by local execution of the vulnerable binary that performs ELF parsing; no remote interaction is required.
Affected Systems
The affected product is GNU Binutils, specifically the 2.47 release. No other versions were mentioned in the advisory. Systems running 2.47 on any operating system are subject to the defect. There is no indication that earlier or later releases are impacted or patched.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity vulnerability. The EPSS score of <1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can supply a crafted ELF file to a local process that uses bfd_elf_set_group_contents can trigger a crash, leading to a denial‑of‑service condition. The exploit has been made publicly available, but no remote or privilege escalation aspects are described.
OpenCVE Enrichment