Impact
The vulnerability occurs in the _bfd_elf_strtab_delref function of the ELF String Table component in GNU Binutils. Manipulating this function can trigger memory corruption, potentially causing process crashes or unstable behaviour. The exploit requires local access, meaning an attacker must have the ability to run code on the affected system.
Affected Systems
GNU Binutils version 2.47 is affected. The flaw resides in the ELF String Table handling code within this distribution.
Risk and Exploitability
With a CVSS score of 4.8, the flaw is rated moderate. The EPSS score indicates a probability of exploitation less than 1%, implying that the vulnerability is unlikely to be actively exploited. The exploit is publicly available but still requires local privileges, and it is not listed in the CISA KEV catalog. Attackers who can execute local code may corrupt memory, leading to crashes or other mitigateable symptoms. Remote exploitation is not supported.
OpenCVE Enrichment