Medium severity5.5NVD Advisory· Published May 18, 2017· Updated May 13, 2026
CVE-2017-9038
CVE-2017-9038
Description
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word offsets.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- blogs.gentoo.org/ago/2017/05/12/binutils-multiple-crashes/nvdPatchThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/98589nvd
- security.gentoo.org/glsa/201709-02nvd
News mentions
0No linked articles in our index yet.