Description
A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Null pointer dereference leading to local denial of service
Action: Patch
AI Analysis

Impact

A weakness was identified in GNU Binutils 2.47. The flaw resides in the function bfd_elf_set_group_contents used to parse the SHT_GROUP section of ELF files. When a maliciously crafted ELF file is processed, the function dereferences a null pointer, causing the vulnerable binary to crash. The issue is triggered by local execution of the vulnerable binary that performs ELF parsing; no remote interaction is required.

Affected Systems

The affected product is GNU Binutils, specifically the 2.47 release. No other versions were mentioned in the advisory. Systems running 2.47 on any operating system are subject to the defect. There is no indication that earlier or later releases are impacted or patched.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium severity vulnerability. The EPSS score of <1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can supply a crafted ELF file to a local process that uses bfd_elf_set_group_contents can trigger a crash, leading to a denial‑of‑service condition. The exploit has been made publicly available, but no remote or privilege escalation aspects are described.

Generated by OpenCVE AI on September 16, 2026 at 07:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any upstream fix or newer Binutils release that addresses the null pointer dereference once available from GNU.
  • If an immediate upgrade cannot be performed, restrict the execution of untrusted ELF binaries or modify the affected binary to bypass SHT_GROUP processing, thereby preventing the vulnerable function from being invoked.
  • Employ input validation or sandboxing for ELF file processing to ensure that malformed files are rejected before reaching the susceptible code path.

Generated by OpenCVE AI on September 16, 2026 at 07:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Title GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:50:27.221Z

Reserved: 2026-09-13T19:21:27.409Z

Link: CVE-2026-90829

cve-icon Vulnrichment

Updated: 2026-09-15T14:50:04.911Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T23:18:59.440

Modified: 2026-09-16T15:28:15.217

Link: CVE-2026-90829

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T22:15:15Z

Links: CVE-2026-90829 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T07:15:04Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference