Impact
The flaw resides in the _bfd_write_merged_section routine of GNU Binutils’ section merge component. null pointer dereference, which crashes the calling process and disrupts any operation that engages the merge function, such as assembling or linking. The result is a denial of service that can affect the stability of build or deployment pipelines.
Affected Systems
GNU Binutils version 2.47 of the binutils package, regardless of platform, is vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score is <1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV. Local attackers who can run or supply input to the affected functions can exploit this flaw.
OpenCVE Enrichment