Description
A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Null Pointer Dereference
Action: Immediate Upgrade
AI Analysis

Impact

The vulnerability resides in GNU Binutils 2.47 within the function elf_x86_64_common_section_index, which is invoked when handling ELF sections. A crafted input can trigger a null pointer dereference during the section index resolution process, causing the target process to crash. The crash results in a denial of service but does not allow an attacker to execute arbitrary code or compromise confidentiality or integrity of the system beyond the affected process.

Affected Systems

The affected product is GNU Binutils, version 2.47. The upstream patch resolving the issue is available in version 2.48, identified by commit 7322e9bc30cb282575a701c307851fd3d66fee68. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium severity. The EPSS score of less than 1% implies that the likelihood of exploitation is very low, and the vulnerability is not currently listed in the CISA KEV catalog. Attack would need to be performed locally on a system that processes untrusted ELF binaries. In environments where local binary execution is restricted or the system rarely handles exotic ELF files, the overall risk is low. However, in high‑value systems where local users can supply binaries, the risk rises because a local user could intentionally trigger the crash.

Generated by OpenCVE AI on September 16, 2026 at 06:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GNU Binutils to version 2.48 or later to eliminate the vulnerability
  • If an upgrade is not immediately possible, apply the patch identified by commit 7322e9bc30cb282575a701c307851fd3d66fee68 to the source code and rebuild Binutils
  • Restrict local users from loading or creating by Binutils; enforce minimum privilege for binaries that invoke Binutils functions

Generated by OpenCVE AI on September 16, 2026 at 06:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component.
Title GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:39:13.272Z

Reserved: 2026-09-15T02:01:16.001Z

Link: CVE-2026-91781

cve-icon Vulnrichment

Updated: 2026-09-15T13:39:09.284Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T09:16:45.153

Modified: 2026-09-16T15:28:36.267

Link: CVE-2026-91781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T06:15:07Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference