Impact
The vulnerability resides in GNU Binutils 2.47 within the function elf_x86_64_common_section_index, which is invoked when handling ELF sections. A crafted input can trigger a null pointer dereference during the section index resolution process, causing the target process to crash. The crash results in a denial of service but does not allow an attacker to execute arbitrary code or compromise confidentiality or integrity of the system beyond the affected process.
Affected Systems
The affected product is GNU Binutils, version 2.47. The upstream patch resolving the issue is available in version 2.48, identified by commit 7322e9bc30cb282575a701c307851fd3d66fee68. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity. The EPSS score of less than 1% implies that the likelihood of exploitation is very low, and the vulnerability is not currently listed in the CISA KEV catalog. Attack would need to be performed locally on a system that processes untrusted ELF binaries. In environments where local binary execution is restricted or the system rarely handles exotic ELF files, the overall risk is low. However, in high‑value systems where local users can supply binaries, the risk rises because a local user could intentionally trigger the crash.
OpenCVE Enrichment