Description
A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Upgrade
AI Analysis

Impact

The vulnerability is a null pointer dereference in the elf_x86_allocate_dynrelocs function of GNU Binutils' Dynamic Relocation Allocation module. The flaw can cause the linker to crash when processing certain ELF objects, leading to a denial of service. It reflects the Weaknesses CWE-404 and CWE-476.

Affected Systems

GNU Binutils version 2.47 (and any build that includes the vulnerable module) is affected. Unpatched installations of binutils on build or link environments are at risk. The vendor provided version 2. the issue requires local access with a public exploit available.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% and non‑listing in CISA KEV suggest a low probability of widespread server that processes untrusted ELF files exposes a local attack surface. Prompt patching eliminates all known impact; if patching is infeasible, mitigating exposure involves restricting dynamic relocation for untrusted workloads and applying system hardening controls.

Generated by OpenCVE AI on September 17, 2026 at 17:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GNU Binutils to version 2.48 or later to remove the null pointer dereference.
  • On systems where binutils is not required for development, uninstall or replace the package toening, such as SELinux, AppArmor, or sandboxing, to limit execution of untrusted ELF binaries and reduce the attack surface.
  • If a patch cannot be applied, isolate environments that compile or process ELF files by using network segmentation or firewall controls to reduce exposure to the vulnerable linker.

Generated by OpenCVE AI on September 17, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:binutils:2.47:*:*:*:*:*:*:*

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended.
Title GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereference
First Time appeared Gnu
Gnu binutils
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu binutils
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T14:01:21.844Z

Reserved: 2026-09-15T02:01:19.557Z

Link: CVE-2026-91782

cve-icon Vulnrichment

Updated: 2026-09-17T14:01:16.935Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T09:16:45.350

Modified: 2026-09-17T14:17:54.113

Link: CVE-2026-91782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference