CRITICAL🇵🇱 Wersja polska

CVE-2017-7226

CVSS 9.1v3.0pub. 2017-03-22upd. 2026-05-13

The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to information disclosure as well.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Gnu Binutils

    APP
    Gnu
    2.28
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-12699CRITICAL9.8PL ✓same product

GNU Binutils: heap-based buffer overflow w funkcji finish_stab (objdump)

CVE-2017-7614CRITICAL9.8PL ✓same product

GNU Binutils: null pointer dereference w elflink.c biblioteki libbfd

CVE-2014-9939CRITICAL9.8PL ✓same product

Stack buffer overflow w GNU Binutils przy przetwarzaniu plików Intel Hex

CVE-2017-6969CRITICAL9.1PL ✓same product

GNU Binutils readelf: heap buffer over-read przy przetwarzaniu plików RL78

CVE-2026-6846HIGH7.8same product

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted ...