VYPR

rpm package

opensuse/binutils&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/binutils&distro=openSUSE%20Tumbleweed

Vulnerabilities (172)

  • CVE-2026-18220HigJul 29, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled rel

  • CVE-2026-15003MedJul 27, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providi

  • CVE-2026-6846HigApr 22, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitr

  • CVE-2026-4647MedMar 23, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being us

  • CVE-2026-3442MedMar 16, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful e

  • CVE-2026-3441MedMar 16, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker ca

  • CVE-2025-69648MedMar 9, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progre

  • CVE-2025-69647MedMar 9, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, res

  • CVE-2025-69652MedMar 6, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate int

  • CVE-2025-69649HigMar 6, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentati

  • CVE-2025-69646MedMar 6, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate,

  • CVE-2025-69645MedMar 6, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leadi

  • CVE-2025-69644MedMar 6, 2026
    affected < 2.47-1.1fixed 2.47-1.1

    An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and

  • CVE-2025-11840LowOct 16, 2025
    affected < 2.47-1.1fixed 2.47-1.1

    A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be

  • CVE-2025-11839LowOct 16, 2025
    affected < 2.47-1.1fixed 2.47-1.1

    A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used

  • CVE-2025-11495LowOct 8, 2025
    affected < 2.45-1.2fixed 2.45-1.2

    A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has

  • CVE-2025-11494LowOct 8, 2025
    affected < 2.45-1.2fixed 2.45-1.2

    A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made publi

  • CVE-2025-11414LowOct 7, 2025
    affected < 2.45-1.2fixed 2.45-1.2

    A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been pu

  • CVE-2025-11413LowOct 7, 2025
    affected < 2.45-1.2fixed 2.45-1.2

    A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and

  • CVE-2025-11412LowOct 7, 2025
    affected < 2.45-1.2fixed 2.45-1.2

    A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclos

Page 1 of 9