PT-2026-91753 · Gnu · Gnu Binutils

·

CVE-2026-90828

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.47
Description A flaw in the ELF Orphan Section Handler component allows a local attacker to cause a null pointer dereference, which occurs when the system attempts to read or write to a memory address that is null, typically leading to a program crash. This issue is located within the elf orphan compatible() function in the ld/ldelf.c file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict local access to the system to minimize the risk of exploitation.

Exploit

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90828
ECHO-53BB-615B-00C3

Affected Products

Gnu Binutils