An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade binutils | Jul 30, 2024 | May 26, 2021 |
| Gentoo Linux | — | Upgrade sys-libs/binutils-libs.Upgrade sys-devel/binutils. | Aug 16, 2022 | May 26, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade binutils-develUpgrade binutils | Sep 29, 2021 | May 26, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade binutils-develUpgrade binutils | Sep 24, 2021 | May 26, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade binutils | Sep 29, 2021 | May 26, 2021 |
| Ubuntu | ubuntu-upgrade-binutils | Nov 19, 2024 | May 26, 2021 | |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub