Description
A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the _bfd_write_merged_section routine of GNU Binutils’ section merge component. null pointer dereference, which crashes the calling process and disrupts any operation that engages the merge function, such as assembling or linking. The result is a denial of service that can affect the stability of build or deployment pipelines.

Affected Systems

GNU Binutils version 2.47 of the binutils package, regardless of platform, is vulnerable.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score is <1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV. Local attackers who can run or supply input to the affected functions can exploit this flaw.

Generated by OpenCVE AI on September 17, 2026 at 19:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Binutils release that contains the fix.
  • If no patch is available, restrict execution of binutils utilities that perform section merging to trusted users only by applying appropriate filesystem permissions or access controls.
  • Monitor the GNU Binutils project for an official patch and apply it promptly when released.

Generated by OpenCVE AI on September 17, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Title GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T19:11:01.185Z

Reserved: 2026-09-13T19:21:30.799Z

Link: CVE-2026-90830

cve-icon Vulnrichment

Updated: 2026-09-15T19:10:56.372Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T23:18:59.620

Modified: 2026-09-16T15:28:03.553

Link: CVE-2026-90830

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T22:30:16Z

Links: CVE-2026-90830 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference