CVE-2026-90830
Undergoing Analysis Undergoing Analysis - In Progress

Null Pointer Dereference in GNU Binutils

Vulnerability report for CVE-2026-90830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: VulDB

Description

A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnu binutils 2.47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a null pointer dereference flaw in GNU Binutils 2.47, specifically in the _bfd_write_merged_section function of the bfd/merge.c file. It occurs during section merging operations and can be triggered locally by an attacker.

Detection Guidance

This vulnerability requires local access to exploit and involves a null pointer dereference in GNU Binutils 2.47. Detection may involve checking installed Binutils versions and examining crash logs or core dumps from applications using the affected component.

Impact Analysis

The vulnerability may cause a denial of service by crashing the application that uses GNU Binutils. Since it requires local access, attackers need prior access to the system to exploit it. Public disclosure means exploit code may be available.

Compliance Impact

This vulnerability, a null pointer dereference in GNU Binutils, primarily affects local system integrity and availability. It does not directly involve data exposure or unauthorized access, which are key concerns for GDPR or HIPAA. Compliance impact would be minimal unless the affected system processes sensitive data under these regulations.

Mitigation Strategies

Immediate mitigation steps include updating GNU Binutils to a patched version if available, restricting local access to untrusted users, and monitoring for crashes in applications linked with Binutils. Since the project has not responded, consider isolating affected systems or disabling the Section Merge functionality if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart