Impact
The vulnerability is a null pointer dereference in the elf_x86_allocate_dynrelocs function of GNU Binutils' Dynamic Relocation Allocation module. The flaw can cause the linker to crash when processing certain ELF objects, leading to a denial of service. It reflects the Weaknesses CWE-404 and CWE-476.
Affected Systems
GNU Binutils version 2.47 (and any build that includes the vulnerable module) is affected. Unpatched installations of binutils on build or link environments are at risk. The vendor provided version 2. the issue requires local access with a public exploit available.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% and non‑listing in CISA KEV suggest a low probability of widespread server that processes untrusted ELF files exposes a local attack surface. Prompt patching eliminates all known impact; if patching is infeasible, mitigating exposure involves restricting dynamic relocation for untrusted workloads and applying system hardening controls.
OpenCVE Enrichment