Gnu · Gnu Binutils · CVE-2026-90828
**Name of the Vulnerable Software and Affected Versions**
GNU Binutils version 2.47
**Description**
A flaw in the ELF Orphan Section Handler component allows a local attacker to cause a null pointer dereference, which occurs when the system attempts to read or write to a memory address that is null, typically leading to a program crash. This issue is located within the `elf orphan compatible()` function in the `ld/ldelf.c` file.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict local access to the system to minimize the risk of exploitation.