The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade sys-devel/binutils. | Oct 30, 2017 | May 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 22, 2017 |
| Suse | — | Upgrade binutils-goldUpgrade binutils-devel-32bitUpgrade cross-spu-binutilsUpgrade cross-ppc-binutilsUpgrade binutils-develUpgrade binutilsUpgrade libctf-nobfd0Upgrade libctf0 | Dec 1, 2017 | May 1, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 1, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub