GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference

CVE Details

Basic Information

Title GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Type cve
Published 2025-07-27T05:32:06.926Z
Modified 2025-07-27T05:32:06.926Z

Product Information

Vendor GNU
Product Binutils
Version 2.44

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A null pointer dereference vulnerability in GNU Binutils 2.44’s BFD Library could allow local attackers to cause a crash, potentially disrupting development environments. Applying the provided patch is recommended to fix this issue.
AI Severity High
AI Vendor GNU
AI Product Binutils
AI Version 2.44

Affected Products

  • GNU Binutils 2.44

Additional Information

CWE List CWE-476, CWE-404
Source VulDB

Description

A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.